Rocket Software UniData/UniVerse unirpc32.dll Uni RPC Service Packet Header Remote Overflow

critical Nessus Plugin ID 51463

Synopsis

A database application installed on the remote host is affected by a buffer overflow vulnerability.

Description

According to its reported version, the Rocket Software UniVerse or UniData install on the remote Windows host is affected by a buffer overflow vulnerability. The application fails to properly validate a size value in a RPC packet header before using it to determine the number of bytes to receive.

An unauthenticated, remote attacker can exploit this to execute arbitrary code on the remote host with SYSTEM level privileges.

Solution

Upgrade to UniData 7.2.8 / UniVerse 10.3.9 or later.

See Also

https://www.zerodayinitiative.com/advisories/ZDI-10-294/

Plugin Details

Severity: Critical

ID: 51463

File Name: rocketsoftware_universe_unidata_code_exec.nasl

Version: 1.10

Type: local

Agent: windows

Family: Windows

Published: 1/12/2011

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: x-cpe:/a:rocketsoftware:unidata

Exploit Ease: No known exploits are available

Patch Publication Date: 12/23/2010

Vulnerability Publication Date: 12/23/2010

Reference Information

BID: 45569