StackDefender ObjectAttributes denial of service
| stackdefender-objectattributes-dos (16879) |
Description:
StackDefender is vulnerable to a denial of service attack, caused by an invalid pointer dereference. By supplying an invalid ObjectAttributes address to the ZwOpenFile or ZwCreateFile function, a remote or local attacker could cause the system to crash.
Consequences:
Denial of Service
Remedy:
Upgrade to the latest version of StackDefender (2.10 or later), available from the NGSEC Web site. See References.
References:
- Full-Disclosure Mailing List, Tue Aug 03 2004 - 12:57:36 CDT: iDEFENSE Security Advisory 08.03.04a: NGSEC StackDefender 1.10 Invalid Pointer Dereference Vulnerability.
- iDEFENSE Security Advisory 08.03.04: NGSEC StackDefender 1.10 Invalid Pointer Dereference Vulnerability.
- NGSEC Web site: Next Generation Security Technologies - ngProducts - StackDefender.
- BID-10849: StackDefender ObjectAttributes Invalid Pointer Dereference Denial Of Service Vulnerability
- CVE-2004-0767: NGSEC StackDefender 1.10 allows attackers to cause a denial of service (system crash) via an invalid address for the ObjectAttribues parameter to the hooks for the (1) ZwCreateFile or (2) ZwOpenFile functions.
Platforms Affected:
- Next Generation Security Technologies StackDefender 1.10
Reported:
Aug 03, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
