Release date:
Updated on:
Affected Systems:
Netmechanic ICA netdemo-tftp Server 4.5.1
Unaffected system:
Netmechanic ICA netdemo-tftp Server 4.6.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52194
Netdemo-http Server provides standard HTTP services on a Windows workstation or Server.
Netdemo-has two vulnerabilities that can be exploited by malicious users to leak sensitive information and control the affected systems.
1) the HTTP server has a boundary error when processing Web requests. A too long URL can cause stack buffer overflow.
2) when processing Web requests, errors on the Traffic Grapher server can be exploited to leak the source code of the netdemo-script (". nd") file.
<* Source: Prabhu S Angadi
Link: http://secunia.com/advisories/48168/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Netmechanic
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.netmechanica.com/products? Prod_id = 1, 1015