SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#790533

RSA Authentication Agent for Web for IIS vulnerable to heap overflow via overly large "chunk"

Overview

RSA Authentication Agent for Web for IIS contains a heap overflow in the handling of chunked input. This could allow a remote, unauthenticated attacker to execute arbitrary code on the server.

I. Description

RSA Authentication Agent software provides access control for networks, web applications, and operating systems. It is used in conjunction with RSA SecurID Authenticators and Authentication Manager software.

RSA Authentication Agent for Web for IIS contains a heap overflow vulnerability. Using chunked transfer-encoding it is possible to overwrite portions of heap memory, allowing execution of arbitrary code. Exploit code for this vulnerability is publicly available.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code with LocalSystem privileges on the vulnerable server.

III. Solution

Upgrade or patch

According to RSA Security:

    To get this new patch and documentation, log on to RSA SecurCare Online at https://knowledge.rsasecurity.com and click "Downloads" in the left navigation menu. Then, click "Fixes by Product", click "RSA SecurID", and "Authentication Agent 5.x", and select the downloads and documentation that pertain to your environment.

Systems Affected

VendorStatusDate NotifiedDate Updated
RSA SecurityUnknown11-May-2005

References


https://knowledge.rsasecurity.com
http://secunia.com/advisories/15222
http://www.w3.org/Protocols/rfc2616/rfc2616-sec3.html#sec3.6.1
http://www.securityfocus.com/bid/13524
http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0039.html
http://www.rsasecurity.com/node.asp?id=2807&node_id
http://www.securityfocus.com/bid/13524

Credit

This vulnerability was reported by Gary O'leary-Steele of Sec-1.

This document was written by Will Dormann, based on the Sec-1 security advisory .

Other Information

Date Public:2005-05-06
Date First Published:2005-05-11
Date Last Updated:2005-11-07
CERT Advisory: 
CVE-ID(s):CAN-2005-1471
NVD-ID(s):CAN-2005-1471
US-CERT Technical Alerts: 
Metric:15.75
Document Revision:10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader