Update Protection against Motorola Timbuktu Pro PlughNTCommand Stack Based Buffer Overflow Vulnerability
| Check Point Reference: | CPAI-2009-203 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Secunia Advisory: SA35533 | |
| Industry Reference(s): | CVE-2009-1394 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Motorola Timbuktu Pro Prior to 8.6.7 | ||
| Vulnerability Description A buffer overflow vulnerability exists in Motorola Timbuktu Pro. Motorola Timbuktu is a remote monitoring and control product available for Microsoft Windows and other operating systems. The flaw is due to a boundary error in data processing. Remote attackers could exploit this vulnerability by sending malformed data to the Timbuktu Pro process. |
||
|
Vulnerability Details The vulnerability is due to boundary errors when handling PlughNTCommand named pipe payloads. Remote attackers could exploit this vulnerability by sending a crafted PlughNTCommand named pipe payload to a vulnerable Motorola Timbuktu server. Successful exploitation would result in execution of arbitrary code. |
Protection Overview
This protection will detect and block invalid requests sent to a particular SMB named pipe.
In order for the protection to be activated, update your Security Gateway/VPN-1 product to the latest IPS/SmartDefense update. For information on how to update IPS/SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.