|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Vulnerability Note VU#790533
RSA Authentication Agent for Web for IIS vulnerable to heap overflow via overly large "chunk"
OverviewRSA Authentication Agent for Web for IIS contains a heap overflow in the handling of chunked input. This could allow a remote, unauthenticated attacker to execute arbitrary code on the server.
I. DescriptionRSA Authentication Agent software provides access control for networks, web applications, and operating systems. It is used in conjunction with RSA SecurID Authenticators and Authentication Manager software.
RSA Authentication Agent for Web for IIS contains a heap overflow vulnerability. Using chunked transfer-encoding it is possible to overwrite portions of heap memory, allowing execution of arbitrary code. Exploit code for this vulnerability is publicly available.
II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code with LocalSystem privileges on the vulnerable server.
III. SolutionUpgrade or patch
According to RSA Security:
To get this new patch and documentation, log on to RSA SecurCare Online at https://knowledge.rsasecurity.com and click "Downloads" in the left navigation menu. Then, click "Fixes by Product", click "RSA SecurID", and "Authentication Agent 5.x", and select the downloads and documentation that pertain to your environment.
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
| RSA Security | Unknown | 11-May-2005 |
References
https://knowledge.rsasecurity.com
http://secunia.com/advisories/15222
http://www.w3.org/Protocols/rfc2616/rfc2616-sec3.html#sec3.6.1
http://www.securityfocus.com/bid/13524
http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0039.html
http://www.rsasecurity.com/node.asp?id=2807&node_id
http://www.securityfocus.com/bid/13524
Credit
This vulnerability was reported by Gary O'leary-Steele of Sec-1.
This document was written by Will Dormann, based on the Sec-1 security advisory .
Other Information
| Date Public: | 2005-05-06 |
| Date First Published: | 2005-05-11 |
| Date Last Updated: | 2005-11-07 |
| CERT Advisory: | |
| CVE-ID(s): | CAN-2005-1471 |
| NVD-ID(s): | CAN-2005-1471 |
| US-CERT Technical Alerts: | |
| Metric: | 15.75 |
| Document Revision: | 10 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
|