OSVDB ID: 20151

Title: RSA Authentication Agent for Web IISWebAgentIF.dll Redirect Overflow

Info

Disclosure

Oct 21, 2005

Discovery

Unknown

Dates

Exploit

Oct 21, 2005

Solution

Unknown

Description

A remote overflow exists in RSA Authentication Agent for Web for IIS. IISWebAgentIF.dll fails to validate the length of the "url" parameter in the "Redirect" method, resulting in a stack-based buffer overflow. With a specially crafted GET request, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public, Exploit Commercial
Disclosure: OSVDB Verified
OSVDB: Web Related, Security Software

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, RSA Security has reportedly released a patch to address this vulnerability.

Products

RSA Security

Authentication Agent for Web for IIS

5.2
5.3

References

Credit

  • H D Moore - hdmmetasploit.com - DigitalOffense


Direct URL: http://osvdb.org/20151