.:[ packet storm ]:.
                           
the internet security encyclopedia
the internet security encyclopedia

 ///  File Name:ZDI-08-075.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of EMC Control Center SAN Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists in the SAN Manager Master Agent service (msragent.exe) which listens by default on TCP port 10444. While processing SST_CTGTRANS requests the process copies packet data into a fixed length stack buffer. Exploitation allows for arbitrary code execution under the context of the SYSTEM user.
Homepage:http://www.zerodayinitiative.com/
File Size:3366
Last Modified:Nov 20 18:24:55 2008
MD5 Checksum:baf5fcd61ddfffefe825752a5e5f8532

 .:. Back