漏洞信息详情
Trend Micro OfficeScan 'cgiRecvFile.exe' 缓冲区溢出漏洞
- CNNVD编号:CNNVD-200809-213
- 危害等级: 高危
- CVE编号: CVE-2008-2437
- 漏洞类型: 缓冲区溢出
- 发布时间: 2008-09-16
- 威胁类型: 远程
- 更新时间: 2009-01-29
- 厂 商: trend_micro
- 漏洞来源: Dyon Balding, Secu...
漏洞简介
Trend Micro OfficeScan 7.3 补丁 4 build 1362,OfficeScan 8.0 和 8.0 SP1, 以及 Client Server Messaging Security 3.6及其他构造的cgiRecvFile.exe中存在基于栈缓冲区溢出。远程攻击者通过提交一个包含长的ComputerName参数的HTTP请求来执行任意代码。
漏洞公告
参考网址
来源: BID
名称: 31139
链接:http://www.securityfocus.com/bid/31139
来源: XF
名称: trendmicro-cgirecvfile-bo(45072)
链接:http://xforce.iss.net/xforce/xfdb/45072
来源: www.trendmicro.com
链接:http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_Win_EN_CriticalPatch_B1361_readme.txt
来源: www.trendmicro.com
链接:http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Win_EN_CriticalPatch_B2424_readme.txt
来源: www.trendmicro.com
链接:http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Patch1_Win_EN_CriticalPatch_B3060_readme.txt
来源: www.trendmicro.com
链接:http://www.trendmicro.com/ftp/documentation/readme/OSCE_7.3_Win_EN_CriticalPatch_B1367_readme.txt
来源: www.trendmicro.com
链接:http://www.trendmicro.com/ftp/documentation/readme/CSM_3.6_OSCE_7.6_Win_EN_CriticalPatch_B1195_readme.txt
来源: SECTRACK
名称: 1020860
链接:http://www.securitytracker.com/id?1020860
来源: BUGTRAQ
名称: 20080912 Secunia Research: Trend Micro OfficeScan "cgiRecvFile.exe" Buffer Overflow
链接:http://www.securityfocus.com/archive/1/archive/1/496281/100/0/threaded
来源: VUPEN
名称: ADV-2008-2555
链接:http://www.frsirt.com/english/advisories/2008/2555
来源: SREASON
名称: 4263
链接:http://securityreason.com/securityalert/4263
来源: MISC
链接:http://secunia.com/secunia_research/2008-35/
来源: SECUNIA
名称: 31342
链接:http://secunia.com/advisories/31342
受影响实体
- Trend_micro Officescan:7.3
- Trend_micro Officescan:7.3:Patch_4
- Trend_micro Officescan:7.0
- Trend_micro Officescan:8.0
- Trend_micro Officescan:8.0:Sp1
补丁
暂无
评论