[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] BakBone Netvault 6.x/7.x Local Stack Buffer Overflow
- To: "Full-Disclosure" <Full-Disclosure@xxxxxxxxxxxxxxxxx>, <vulnwatch@xxxxxxxxxxxxx>
- Subject: [Full-disclosure] BakBone Netvault 6.x/7.x Local Stack Buffer Overflow
- From: "class101@xxxxxxxxxxxxx" <class101@xxxxxxxxxxxxx>
- Date: Fri, 1 Apr 2005 16:51:53 +0200
According to their website (bakbone.com),
BakBone Netvault 6.x/7.x is a professional backup software with several
offices in the world and some pro customers as Apple, AT&T, Pirelli, LMU,
HP, NIP,NASA, etc....
A Vulnerability exists in the configure.cfg file
advisory: class101.org/netv-locsbof.pdf
poc: class101.org/36/55/op.php
recommendation: to set stricts acl rules on this file.
-------------------------------------------------------------
class101
Jr. Researcher
Hat-Squad.com
-------------------------------------------------------------
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/