|Main Archive Page > Month Archives > full-disclosure-uk archives|
ZDI-07-024: Trend Micro ServerProtect EarthAgent Stack Overflow
http://www.zerodayinitiative.com/advisories/ZDI-07-024.html May 7, 2007
The specific flaw exists in the EarthAgent.exe daemon, bound by default on TCP port 3628 and exposing the following DCE/RPC interface through TmRpcSrv.dll:
/* opcode: 0x00, address: 0x65741030 */
error_status_t sub_65741030 (
[in] handle_t arg_1,
[in] long arg_2,
[in][size_is(arg_4)] byte arg_3,
[in] long arg_4,
[out][size_is(arg_6)] byte arg_5,
[in] long arg_6
A sub-function within this interface is vulnerable to a stack overflow due an unbounded call to wcscpy().
Researchers interested in getting paid for their security research through the ZDI can find more information and sign-up at:
The ZDI is unique in how the acquired vulnerability information is used. 3Com does not re-sell the vulnerability details or any exploit code. Instead, upon notifying the affected product vendor, 3Com provides its customers with zero day protection through its intrusion prevention technology. Explicit details regarding the specifics of the vulnerability are not exposed to any parties until an official vendor patch is publicly available. Furthermore, with the altruistic aim of helping to secure a broader user base, 3Com provides this vulnerability information confidentially to security vendors (including competitors) who have a vulnerability protection or mitigation product.