Overview
The eIQnetworks Enterprise Security Analyzer Syslog server contains a buffer overflow vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
Description
Enterprise Security Analyzer eIQnetworks Enterprise Security Analyzer (ESA) "... provides essential real-time security intelligence to help decipher hacker/virus behavior, combat security threats and meet regulatory compliance requirements across the entire IT infrastructure – network devices and hosts." ESA is also provided on an OEM basis as Astaro Report Manager, Fortinet FortiReporter, iPolicy Security Reporter, SanMina Viking Multi-Log Manager, Secure Computing G2 Security Reporter, and Top Layer Network Security Analyzer. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code on a system running the vulnerable Syslog component. |
Solution
Apply an update |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.eiqnetworks.com/support/Security_Advisory.pdf
- http://www.eiqnetworks.com/products/enterprisesecurity/EnterpriseSecurityAnalyzer/ESA_2.5.0_Release_Notes.pdf
- http://www.zerodayinitiative.com/advisories/TSRT-06-03.html
- http://www.zerodayinitiative.com/advisories/ZDI-06-023.html
- http://secunia.com/advisories/21211/
- http://secunia.com/advisories/21213/
- http://secunia.com/advisories/21214/
- http://secunia.com/advisories/21215/
- http://secunia.com/advisories/21217/
- http://www.auscert.org.au/6544
Acknowledgements
This vulnerability was disclosed by TippingPoint, who in turn credit Cody Pierce.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2006-3838 |
Severity Metric: | 34.79 |
Date Public: | 2006-07-26 |
Date First Published: | 2006-08-01 |
Date Last Updated: | 2007-01-18 19:06 UTC |
Document Revision: | 14 |