>> EMC DiskXtender Code Execution and Security Bypass Vulnerabilities
Title : EMC DiskXtender Code Execution and Security Bypass Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1198 CVE ID : CVE-2008-0961 - CVE-2008-0962 - CVE-2008-0963
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-11
Technical Description
Multiple vulnerabilities have been identified in EMC DiskXtender, which could be exploited by remote attackers to bypass security restrictions and take complete control of an affected system.
The first issue is caused by an error in the authentication code that contains a hard-coded login and password, which could allow remote attackers to gain administrative access to a vulnerable server via the RPC interface.
The second vulnerability is caused by a buffer overflow error in the File System Manager when handling specially crafted RPC requests, which could be exploited by remote attackers to crash an affected application or execute arbitrary code.
The third issue is caused by a format string error when handling user-supplied RPC requests, which could be exploited by remote attackers to crash an affected application or execute arbitrary code.