APP: Quest One Identity Privilege Manager Buffer Overflow

Signature attempts to capture buffer Overflow in Quest One Identity Privilege Manager for Unix. This may allows remote attackers to obtain full access to the policy server.

Extended Description

Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon.

Affected Products

Quest privilege_manager_for_unix

Short Name
APP:MISC:CVE-2017-6553-BOF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Buffer CVE-2017-6553 Identity Manager One Overflow Privilege Quest
Release Date
10/17/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
Port
tcp/12345
False Positive
Unknown
Vendors

Quest

CVSS Score

10.0

Found a potential security threat?