EMC RepliStor Multiple Remote Heap Based Buffer Overflows

critical Nessus Plugin ID 35467

Synopsis

The remote software is affected by multiple vulnerabilities.

Description

According to its version, the installation of EMC RepliStor Server on the remote host is affected by multiple heap overvlow vulnerabilities. By sending a specially crafted request, an unauthorized attacker could execute arbitrary code with SYSTEM level privileges.

Solution

Upgrade to RepliStor 6.1 SP5 / 6.2 SP4 or later.

See Also

http://www.nessus.org/u?dade10b4

Plugin Details

Severity: Critical

ID: 35467

File Name: emc_replistor_multiple.nasl

Version: 1.9

Type: remote

Published: 1/27/2009

Updated: 7/10/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Required KB Items: EMC/RepliStor/Version

Exploit Ease: No known exploits are available

Reference Information

CVE: CVE-2007-6426

BID: 27915

CWE: 119