Overview
RSA Authentication Agent for Web for IIS contains a heap overflow in the handling of chunked input. This could allow a remote, unauthenticated attacker to execute arbitrary code on the server.
Description
RSA Authentication Agent software provides access control for networks, web applications, and operating systems. It is used in conjunction with RSA SecurID Authenticators and Authentication Manager software. RSA Authentication Agent for Web for IIS contains a heap overflow vulnerability. Using chunked transfer-encoding it is possible to overwrite portions of heap memory, allowing execution of arbitrary code. Exploit code for this vulnerability is publicly available. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code with LocalSystem privileges on the vulnerable server. |
Solution
Upgrade or patch |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- https://knowledge.rsasecurity.com
- http://secunia.com/advisories/15222
- http://www.w3.org/Protocols/rfc2616/rfc2616-sec3.html#sec3.6.1
- http://www.securityfocus.com/bid/13524
- http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0039.html
- http://www.rsasecurity.com/node.asp?id=2807&node_id
- http://www.securityfocus.com/bid/13524
Acknowledgements
This vulnerability was reported by Gary O'leary-Steele of Sec-1.
This document was written by Will Dormann, based on the Sec-1 security advisory .
Other Information
CVE IDs: | CVE-2005-1471 |
Severity Metric: | 15.75 |
Date Public: | 2005-05-06 |
Date First Published: | 2005-05-11 |
Date Last Updated: | 2005-11-07 15:46 UTC |
Document Revision: | 11 |