[] NeoSense

Aventail Connect 4.1.2.13 - Hostname Remote Buffer Overflow

Author: Thomas Pollet
type: dos
platform: windows
port: nan
date_added: 2007-04-30 
date_updated: 2013-12-01 
verified: 1 
codes: CVE-2007-2434;OSVDB-35671 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/23717/info

Aventail Connect is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.

An attacker may exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts wlll result in a denial of service.

This issue affects Aventail Connect 4.1.2.13; other versions may also be affected.

ssh $(perl -e 'print 'a'x2200')