Executive Summary
| Summary | |
|---|---|
| Title | LANDesk QIP service buffer overflow vulnerability |
| Informations | |||
|---|---|---|---|
| Name | VU#538011 | First vendor Publication | 2008-09-17 |
| Vendor | VU-CERT | Last vendor Modification | 2008-09-17 |
| Severity (Vendor) | N/A | Revision | M |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 10 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Vulnerability Note VU#538011LANDesk QIP service buffer overflow vulnerabilityOverviewThe LANDesk Management Suite Intel QIP service contains a buffer overflow vulnerability.I. DescriptionThe LANDesk Intel QIP Server Service is used to configure policy management. The Intel QIP service allows LANDesk Agents to report status and make certain software requests.A buffer overflow vulnerability exists in the Intel QIP service (Qipsrvr.exe). II. ImpactA remote, unauthenticated attacker may be able to execute code with system privileges.III. SolutionUpgradeLANDesk has released updates to address this issue. See LANDesk DOC-3276 for more information. Systems Affected
References CreditThanks to LANDesk for technical information that was used in this document. This issue was reported to LANDesk by TippingPoint DVLabs. This document was written by Ryan Giobbi. Other Information
|
Original Source
| Url : http://www.kb.cert.org/vuls/id/538011 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 2 | |
| Application | 2 | |
| Application | 2 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 48123 | LANDesk Multiple Products QIP Server Service (qipsrvr.exe) Heal Request Packe... |

VU#538011
(Critical)





