Release date:
Updated on:
Affected Systems:
Rocketsoftware Rocket U2 UniData 7.x
Description:
--------------------------------------------------------------------------------
Rocket U2 contains two extended relational databases: UniData and UniVerse. It has an integrated development environment for fast, economical, and vertical application development.
When parsing certain calls in versions earlier than Rocket U2 UniData 7.2.12, The unidata72 RPC interface of the unirpcd server has an error. Attackers can exploit this vulnerability to execute arbitrary commands at the system level or root permission on the target host.
<* Source: Thorsten tüllmann
Link: http://secunia.com/advisories/49479/
Https://www.upsploit.com/index.php/advisories/view/UPS-2012-0012
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Rocketsoftware
--------------
Rocketsoftware has released a Security Bulletin (UPS-2012-0012) and patches for this:
UPS-2012-0012: Authentication bypass in Unidata leads to remote command execution
Link: https://www.upsploit.com/index.php/advisories/view/UPS-2012-0012