WellinTech KingView 6.53 < 2011-11-20 HistoryServer.exe nettransdll.dll Module Op-code 3 Packet Parsing Remote Overflow
Critical Nessus Plugin ID 59376
SynopsisThe remote Windows host contains an application that is affected by a remote buffer overflow vulnerability.
DescriptionAccording to its version, the instance of WellinTech KingView installed on the remote Windows host is affected by a remote buffer overflow vulnerability. A flaw exists inside of 'nettransdll.dll' that may permit unauthenticated, remote attackers to execute arbitrary code in the context of the application. 'HistorySrv.exe' listens on port 777. When a specially-crafted request is received requesting service opcode 0x03, a buffer is allocated based on a size field in the request. Once the buffer has been created, data from the packet is copied into the buffer based on yet another size field. By making the buffer size field smaller than the data size field, a heap overflow can be accomplished.
SolutionInstall the patch referenced in the vendor's advisory.