>> LANDesk Products QIP Server Service Buffer Overflow Vulnerability
Title : LANDesk Products QIP Server Service Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-2588 CVE ID : CVE-2008-2468 CWE ID : CWE-119
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-16
Technical Description
A vulnerability has been identified in LANDesk products, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by a buffer overflow error within the QIP Server Service (qipsrvr.exe) when processing malformed "heal" requests sent to port 12175/TCP, which could be exploited by remote attackers to crash an affected service or execute arbitrary code with SYSTEM privileges.