EMC Documentum eRoom Indexing Server Hummingbird Client Connector Buffer Overflow

critical Nessus Plugin ID 55732

Synopsis

A text indexing service on the remote host has a buffer overflow vulnerability.

Description

The Hummingbird Client Connector, bundled with EMC Documentum eRoom's Indexing Server, has a buffer overflow vulnerability. Making an unspecified request can result in a stack-based buffer overflow. A remote, unauthenticated attacker could exploit this to execute arbitrary code.

Documentum eRoom versions 7.x are affected.

Solution

Upgrade to EMC Documentum eRoom 7.4.3.f or later.

See Also

https://www.zerodayinitiative.com/advisories/ZDI-11-236/

https://www.securityfocus.com/archive/1/518897/30/0/threaded

Plugin Details

Severity: Critical

ID: 55732

File Name: emc_eroom_index_server_bof.nasl

Version: 1.9

Type: remote

Agent: windows

Family: Windows

Published: 7/29/2011

Updated: 11/15/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:emc:documentum_eroom

Required KB Items: SMB/Registry/Enumerated

Exploit Ease: No known exploits are available

Patch Publication Date: 7/15/2011

Vulnerability Publication Date: 7/15/2011

Reference Information

CVE: CVE-2011-1741

BID: 48712