Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] Multiple vulnerabilities in CommuniGate Pro Server |
|---|---|
| Date: | Sat, 28 Jan 2006 10:15:17 +0300 (MSK) |
I. DESCRIPTION CommuniGate Pro Core Server from CommuniGate Systems provides robust cross-platform groupware applications, enabling a cost effective, easy to manage communications platform. For more info visit http://www.stalker.com II. DETAILS During testing of CommuniGate Pro Server 5.0.6 using ProtoVer LDAP testsuite version 1.1 multiple vulnerabilities in LDAP component of CommuniGate Pro have been uncovered. The vulnerabilities could be used by a remote unauthenticated attacker to crash the server or in the worst case to execute the arbitrary code. III. VENDOR RESPONSE The vendor has released 5.0.7 version which addresses these issues. Quote from http://www.stalker.com/CommuniGatePro/History.html: """ 5.0.7 27-Jan-05 Bug Fix: Foundation: 3.0: Negative BER lengths were processed incorrectly. """ IV. HISTORY 24 Jan 2006 - initial vendor contact 25 Jan 2006 - vendor received a fully-functional trial of ProtoVer LDAP testsuite 26 Jan 2006 - vendor successfully reproduced the problems 27 Jan 2006 - vendor released the fixed version V. CREDIT All these issues were found using GLEG Ltd's ProtoVer LDAP testsuite: http://www.gleg.net/protover_ldap.shtml _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Azbb v1.1.00 Cross-Site Scripting, roozbeh_afrasiabi |
|---|---|
| Next by Date: | The WorldsEnd.NET - Free Ping Script, written in PHP (2 vulns), cvh |
| Previous by Thread: | Azbb v1.1.00 Cross-Site Scripting, roozbeh_afrasiabi |
| Next by Thread: | The WorldsEnd.NET - Free Ping Script, written in PHP (2 vulns), cvh |
| Indexes: | [Date] [Thread] [Top] [All Lists] |