Rocket Software UniData/UniVerse unirpc32.dll Uni RPC Service Packet Header Remote Overflow

This script is Copyright (C) 2011-2016 Tenable Network Security, Inc.


Synopsis :

A database application installed on the remote host is affected by a
buffer overflow vulnerability.

Description :

According to its reported version, the Rocket Software UniVerse or
UniData install on the remote Windows host is affected by a buffer
overflow vulnerability. The application fails to properly validate a
size value in a RPC packet header before using it to determine the
number of bytes to receive.

An unauthenticated, remote attacker can exploit this to execute
arbitrary code on the remote host with SYSTEM level privileges.

See also :

http://www.zerodayinitiative.com/advisories/ZDI-10-294/

Solution :

Upgrade to UniData 7.2.8 / UniVerse 10.3.9 or later.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.7
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows

Nessus Plugin ID: 51463 ()

Bugtraq ID: 45569

CVE ID:

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now