Title : OpenPegasus PAM Authentication Multiple Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2008-0063 CVE ID : CVE-2007-5360 - CVE-2008-0003
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-01-08
Technical Description
Multiple vulnerabilities have been identified in OpenPegasus, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system.
The first issue is caused by a buffer overflow error in the "Cimservera::PAMCallback()" [cimservera.cpp] function when processing an overly long password, which could be exploited by remote unauthenticated attackers to crash an affected application or execute arbitrary code.
The second vulnerability is caused by a buffer overflow error in the PAM authentication module when handling malformed data, which could be exploited by remote attackers to crash an affected application or execute arbitrary code.