Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: June 29, 2009
Lauren Gerber
1
Vote
0

Serving A Buffer Overflow to the Unisys Business Information Server

 

During the course of your life, I am sure you have heard many people refer to "no news" as "good news". If that is the case and no news actually means good news, then I can apply the same logic and tell you that I have some bad news for you. This news is about a stack based buffer overflow vulnerability that has been reported in Unisys. This vulnerability may allow malicious characters to effectively execute arbitrary codes, with the use of the privileges of the affected server.vulnerable.jpg

The risks with regard to this vulnerability are that malicious individuals will be able to send a packet directly to the Unisys Business information server. This could be performed via a TCP port. The dangers with regard to this actually happening, is that a malicious person would be able to go as far as corrupting the stack based memory as well as being able to effectively execute arbitrary code.Unisys.jpg

It is crucial for Unisys Business information server users to be aware of the factor that this vulnerability can only be carried out, if manipulated network based attack software is used. In order for this to be effective, the software that needs to be use has to be software which has been designed with the primary goal of being able to effectively exploit this exact vulnerability.

I do have some moderately good news for you, which is that a patch for this vulnerability does exit. However this patch, unfortunately, can only be used on a Windows 2003/Windows 2008 Server. There also needs to be an installed version of the Business Information Server 10.1. The majority of Windows users, should be more than familiar with the Windows 2003 and Windows 2008 Server versions. Some of the files of the Windows Server 2003 may include but are not limited to the following: a302.sys, b5820w2k.sys, CasPol.exe, davcprox.dll, e1000325.sys as well as faxinit.exe.

It may be useful, and is highly suggested, that all users always back up a copy of their data. This will prove useful if an operational error occurs, when you are busy installing this patch. The risks of an installation error are likely and therefore it is important for users to take the concept of a backing up data seriously. It can thus be quoted in conclusion:"Storing files on a computer without any backup is like putting all your eggs in one basket, and then throwing it off a very high cliff. They may be safe for a while, but eventually things will get messy."- T.E. Ronneberg

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 12, 2010
Anyone would panic with bizarre behaviour of your computer with warnings, music flashing, etc. Don't... more..
March 12, 2010
nicejerk - Microsoft no longer supports (ie cares about anything bad happening) with XP. They don't... more..
March 12, 2010
To re-enable shortcuts and exe's delete registry keys HKCUSoftwa .. oftwareclasses.exe &/or... more..
more comments..
rss
Home > Computer Security > Serving A Buffer Overflow to the Unisys Business Information Server