InterSystems Caché and Ensemble Remote Buffer Overflow Vulnerability


Description   A vulnerability has been identified in InterSystems Caché and Ensemble, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in the CSP Gateway components when processing overly long HTTP requests (e.g. supplied via the "csp/sys/mgr/UtilConfigHome.csp" file), which could be exploited by remote attackers to crash an affected application or execute arbitrary code.
     
Vulnerable Products   Vulnerable Software:
InterSystems Caché version 2009.1.0.xInterSystems Caché version 2009.1.1.xInterSystems Caché version 2009.1.2.xInterSystems Ensemble version 2009.1.0.xInterSystems Ensemble version 2009.1.1.xInterSystems Ensemble version 2009.1.2.x
     
Solution   Apply patch :ftp.intersystems.com/pub/cache/patches/CSP_Gateway_Security_Alert.zip
     
CVE  
     
References   ftp://ftp.intersystems.com/pub/cache/patches/CSP_Gateway_Security_Alert.zip
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Critical 

 Vulnerability First Public Report Date 
2009-12-14 

 Target Type 
Server 

 Possible exploit 
Local & Remote