Release date:
Updated on:
Affected Systems:
QNX Phindows 3.0.44
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53485
Phrelay and phindows/phditto are based on private protocols and allow the Photon graphical environment of the server on another machine.
QNX Phindows 3.0.44the phindows.exe has a boundary error in the response time of the processing server. A specially crafted TCP response message can cause stack buffer overflow and arbitrary code execution. Successful exploitation requires the user to be connected to a malicious Photon session server.
<* Source: Luigi Auriemma (aluigi@pivx.com)
Link: http://aluigi.altervista.org/adv/qnxph_1-adv.txt
Http://secunia.com/advisories/49090/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
QNX
---
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.qnx.com/