Title: Netwin NWAuth Buffer Overflow Vulnerabilities
Severity: HIGH
Description:
The Netwin Authentication module, or NWAuth, is an external authentication module used by several Netwin products.
NWAuth contains numerous boundary condition errors in its handling of arguments passed with certain command line arguments. If an argument of excessive length is passed to the program, a stack overrun occurs and the extraneous data overwrites stack variables. This condition may permit an attacker to take control of the process. This would be accomplished by replacing a function return address with a pointer to supplied shellcode.
It may be possible for an attacker to exploit these buffer overflows to execute arbitrary code through a service that uses NWAuth. This could lead to full system compromise.
Affected Products:
- NetWin DMail 2.5.0 d
- NetWin DMail 2.7.0
- NetWin DMail 2.7.0 q
- NetWin DMail 2.7.0 r
- NetWin DMail 2.8.0 e
- NetWin DMail 2.8.0 f
- NetWin DMail 2.8.0 g
- NetWin DMail 2.8.0 h
- NetWin DMail 2.8.0 i
- NetWin SurgeFTP 1.0.0 b
- NetWin SurgeFTP 2.0.0 B
- NetWin SurgeFTP 2.0.0 a
References:
- NetWin Limited: NetWin Homepage
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.