Release date:
Updated on:
Affected Systems:
Uptimesoftware up. time Agent 5.0.1
Description:
--------------------------------------------------------------------------------
Up. time Agent is IT monitoring software.
Up. time Agent 5.0.1 has a security vulnerability when processing the "chk4" command. Attackers can exploit this vulnerability through specially crafted data packets to cause stack buffer overflow and arbitrary code execution.
<* Source: Denis Andzakovic
Link: http://secunia.com/advisories/55790/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Uptimesoftware
--------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.uptimesoftware.com/
Http://www.security-assessment.com/files/documents/advisory/Up.Time%20Agent%205.0.1%20Stack%20Overflow.pdf