>> LiveData Servers Remote Buffer Overflow and Denial of Service Vulnerabilities
Title : LiveData Servers Remote Buffer Overflow and Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2007-1633 CVE ID : CVE-2007-2489 - CVE-2007-2490
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-05-03
Technical Description
Two vulnerabilities have been identified in LiveData Protocol Server, which could be exploited by attackers to remotely cause a denial of service or take complete control of an affected system.
The first issue is caused by a buffer overflow error in the "LiveDataServer" service when processing specially crafted requests for WSDL files (port 8080), which could be exploited by remote unauthenticated attackers to crash an affected service or execute arbitrary code.
The second vulnerability is caused by an error when processing malformed Connection-Oriented Transport Protocol (COTP) packets, which could be exploited by attackers to cause a vulnerable server to terminate abnormally resulting in a denial of service condition.