SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Geo++(R) GNCASTER: Insecure handling of long URLs


Arrow  SecurityAlert : 7002
Arrow  CVE : CVE-2010-0552
Arrow  CWE : CWE-20
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : No
Arrow  Exploit Available : Yes
Arrow  Credit : RedTeam
Arrow  Published : 08.02.2010

Arrow  Affected Software : geopp:geo%2B%2B_gncaster:1.4.0.7 and previous versions
geopp:geo%2B%2B_gncaster:1.4.0.0



Arrow  Advisory Content :  

Advisory: Geo++(R) GNCASTER: Insecure handling of long URLs

During a penetration test, RedTeam Pentesting discovered that the
GNCASTER software does not handle long URLs correctly. An attacker can
use this to crash the server software or potentially execute code on the
server.

Details
=======

Product: Geo++(R) GNCASTER
Affected Versions: <= 1.4.0.7
Fixed Versions: 1.4.0.8
Vulnerability Type: Memory corruption
Security Risk: high
Vendor URL: http://www.geopp.de
Vendor Status: notified
Advisory URL: http://www.redteam-pentesting.de/advisories/rt-sa-2010-001
Advisory Status: published
CVE: TBA
CVE URL: TBA

Introduction
============

"Geo++(R) GNCASTER is the Geo++ implementation of a NTRIP caster. NTRIP
is a protocol within RTCM to provide GNSS information via Internet."

(from the vendor's homepage)

More Details
============

The GNCaster software allows communication with clients through a subset
of the HTTP protocol. If an attacker sends an HTTP GET request for a
nonexistent URL path and the request is less than 988 bytes long, the
server reacts with an HTTP 404 error and the message

File "/AAAAAA[...]AAAA" not found on this server.

If the URL path length is 988 bytes or more, the HTTP 404 error is still
returned but the server thread stops before returning the message above.

If attackers send a sequence of such requests in quick succession, the
server can be reproducibly crashed. RedTeam Pentesting believes it is
also possible to exploit this vulnerability to execute code on the
server.

Proof of Concept
================

The following command can be used to crash the server if it is called
multiple times:

$ curl -i "http://gncaster.example.com:1234/`perl -e 'printf "A"x988'`"

Workaround
==========

A vulnerable server could be protected from this vulnerability by an
application layer firewall that filters overly long HTTP GET requests.

Fix
===

Update GNCASTER to version 1.4.0.8.

Security Risk
=============

This vulnerability can be used for very efficient DoS attacks. This is
especially serious as GNCaster is a real time application that is
typically used by multiple mobile clients that rely on a functioning
server. The vulnerability could potentially also be leveraged to remote
code execution on the server. The risk is therefore regarded as high.

History
=======

2009-07-06 Vulnerability identified during a penetration test
2009-07-14 Meeting with customer
2009-12-01 Vendor releases fixed version
2010-01-27 Advisory released

RedTeam Pentesting GmbH
=======================

RedTeam Pentesting offers individual penetration tests, short pentests,
performed by a team of specialised IT-security experts. Hereby, security
weaknesses in company networks or products are uncovered and can be
fixed immediately.

As there are only few experts in this field, RedTeam Pentesting wants to
share its knowledge and enhance the public knowledge with research in
security related areas. The results are made available as public
security advisories.

More information about RedTeam Pentesting can be found at
http://www.redteam-pentesting.de.

--
RedTeam Pentesting GmbH Tel.: +49 241 963-1300
Dennewartstr. 25-27 Fax : +49 241 963-1304
52068 Aachen http://www.redteam-pentesting.de/
Germany Registergericht: Aachen HRB 14004
Geschäftsführer: Patrick Hof, Jens Liebchen, Claus R. F. Overbeck
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEVAwUBS2A0E9G/HXWsgFSuAQLJeggAzJXE3eZR1aJRPhKvw1fO6R0XUmVD2qsn
4h53PswQvtpdfwH78dCY6kutmmqUlgoT4iwGvkBfUe/L9dhjScNM0h/A4AKu5KFX
d3ECcbPCY6rob78RdSISAJXZXUtlRLHZYKhEMgIy2qK/x3Z6bUU/czYoezrsHLLQ
QS/YU4cFOCfKg+T761AU2wtLXZ1nly7NljQL2oXW8GBZOYlHaQaSPnkHl75KZDKh
6YSsKW7Lnl/6O2jadssrdoaQplNygHS/LjbqHapjxFHv+ALVPxLq+Mas0tjB+VUi
ZQucflb0vkRE25zTXPPsW6XrqIfQS9TpmSiP6gsazPbSSZCzZQAUtw==
=P2mF
-----END PGP SIGNATURE-----




Arrow  References :

http://xforce.iss.net/xforce/xfdb/55974
http://www.securityfocus.com/archive/1/archive/1/509194/100/0/threaded
http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-001/-geo-r-gncaster-insecure-handling-of-long-urls
http://secunia.com/advisories/38323
http://osvdb.org/62011




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.