Synopsis
The remote service has a buffer overflow.
Description
A stack overflow vulnerability exists in the DiskPulse Server installed on the remote host.
By sending a specially crafted message to the server, a remote attacker can leverage this vulnerability to execute arbitrary code on the server with SYSTEM privileges.
Note that Nessus checked for this vulnerability by sending a specially crafted packet and checking the response, without crashing the service.
All 2.x versions 2.2 and below are known to be affected, and others may be as well.
Solution
Upgrade to version 2.3 as it appears to address the issue.
Plugin Details
File Name: diskpulse_stack_overflow.nasl
Agent: windows
Supported Sensors: Nessus
Vulnerability Information
Exploit Ease: Exploits are available
Patch Publication Date: 10/12/2010
Vulnerability Publication Date: 10/12/2010
Exploitable With
ExploitHub (EH-12-633)
Reference Information
BID: 43919