CERT-In Vulnerability Note
CIVN-2005-0106
RSA Authentication Agent for Web "Redirect" Buffer Overflow Vulnerability
Original Issue Date:October 26, 2005
Severity Rating: HIGH
Systems Affected
RSA Security Authentication Agent for Web for IIS 5.2 RSA Security Authentication Agent for Web for IIS 5.3
Overview
A buffer overflow vulnerability has been identified in 'RSA Authentication Agent for Web' for Internet Information Services, which could be exploited by remote attackers to cause a DoS or potentially to compromise a vulnerable system.
Description
RSA Security Authentication Agent for Web for IIS is an ISAPI filter , Secure ID Web Agent for IIS which runs in-process with inetinfo.exe. This vulnerability is caused due to a boundary error in IISWebAgentIF.dll.
This can be exploited to cause a stack-based buffer overflow by sending a GET request with an overly long "url" parameter in the "Redirect" method. Successful exploitation will result in the termination and potential restart of the IIS service.
Solution
It has been reported that RSA Security has released a patch to address this vulnerability.
https://knowledge.rsasecurity.com/dlcpages/rsa_securid/securid_dlc_aaweb.asp
Vendor Information
http://rsasecurity.com/
References
Secunia
http://secunia.com/advisories/17281/
OSVDB
http://www.osvdb.org/20151
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|