xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

NetScreen ScreenOS远程可复位漏洞


发布时间:2002-05-31
更新时间:2002-05-31
严重程度:
威胁程度:远程拒绝服务
错误类型:意外情况处置错误
利用方式:服务器模式

BUGTRAQ ID:4842

受影响系统
NetScreen ScreenOS 3.0.0r4
NetScreen ScreenOS 3.0.0r3
NetScreen ScreenOS 3.0.0r2
NetScreen ScreenOS 3.0.0r1
NetScreen ScreenOS 3.0.0
NetScreen ScreenOS 2.8.0r1
NetScreen ScreenOS 2.5 r6
NetScreen ScreenOS 2.5 r2
NetScreen ScreenOS 2.5 r1
NetScreen ScreenOS 2.5
NetScreen ScreenOS 2.6.1 r5
NetScreen ScreenOS 2.6.1 r4
NetScreen ScreenOS 2.6.1 r3
NetScreen ScreenOS 2.6.1 r2
NetScreen ScreenOS 2.6.1 r1
NetScreen ScreenOS 2.6.1
NetScreen ScreenOS 2.7.1 r3
NetScreen ScreenOS 2.7.1 r2
NetScreen ScreenOS 2.7.1 r1
NetScreen ScreenOS 2.7.1
NetScreen ScreenOS 2.10 r4
NetScreen ScreenOS 2.10 r3
NetScreen ScreenOS 3.0.1 r1
详细描述
通过向NetScreen ScreenOS的WEB接口提交超长的用户名后可导致设备停止响应。

问题发生在缓冲未正确检查,存在执行任意代码的可能。

测试代码
见描述

解决方案
升级SCREEN OS程序到最高版本:

NetScreen ScreenOS 3.0.0r4:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 3.0.0r3:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 3.0.0r2:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 3.0.0r1:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 3.0.0:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.8.0r1:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.5 r6:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.5 r2:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.5 r1:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.5:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.6.1 r5:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.6.1 r4:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.6.1 r3:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.6.1 r2:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.6.1 r1:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.6.1:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.7.1 r3:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.7.1 r2:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.7.1 r1:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.7.1:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.10 r4:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 2.10 r3:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

NetScreen ScreenOS 3.0.1 r1:

NetScreen Upgrade ScreenOS 3.0.1r2
http://www.netscreen.com/support/updates.html

相关信息
Quentyn Taylor <quentyn@fotango.com>.
参考:http://online.securityfocus.com/archive/1/274240
相关主页:http://www.netscreen.com/index.html