Rocket Software UniRPC Service Packet Header Remote Overflow (uncredentialed check)

This script is Copyright (C) 2011-2012 Tenable Network Security, Inc.


Synopsis :

A database application installed on the remote host is affected by a
buffer overflow vulnerability.

Description :

According to its reported version, the Rocket Software UniVerse or
UniData install on the remote Windows host is affected by a buffer
overflow vulnerability. The application fails to properly validate a
size value in a RPC packet header before using it to determine the
number of bytes to receive.

An unauthenticated, remote attacker can exploit this to execute
arbitrary code on the remote host with SYSTEM level privileges.

See also :

http://www.zerodayinitiative.com/advisories/ZDI-10-294/
http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0598.html

Solution :

Upgrade to UniData 7.2.8 / UniVerse 10.3.9 or later.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.4
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Databases

Nessus Plugin ID: 51575 ()

Bugtraq ID: 45569

CVE ID: