Summary
This host is running Sync Breeze Server and is prone to remote stack buffer overflow vulnerability
Impact
Successful exploitation will allow attackers to crash an affected service or execute arbitrary code with elevated privileges.
Impact Level: Application
Solution
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore.
General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
Insight
The flaw is caused by a buffer overflow error in the 'syncbrs.exe' service when processing overly long login requests sent to port 9121/TCP.
Affected
Sync Breeze Server version 2.2.30 and prior
References
Severity
Classification
-
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities
- XnView Multiple Image Decompression Heap Overflow Vulnerabilities (Windows)
- SquidGuard Multiple Buffer Overflow Vulnerabilities
- Wireshark BER Dissector Stack Consumption Vulnerability (Mac OS X)
- VLC Media Player 'MP4_ReadBox_skcr()' Buffer Overflow Vulnerability (Windows)
- Tcptrack Command Line Parsing Heap Based Buffer Overflow Vulnerability