CVE Database
/

CVE-2005-1929

Back to search

CVE-2005-1929

Published: Dec 14, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.

VendorProductVersions

n/a

n/a

affected
n/a

References

18038
third-party-advisory
x_refsource_SECUNIA
257
third-party-advisory
x_refsource_SREASON
1015358
vdb-entry
x_refsource_SECTRACK
21772
vdb-entry
x_refsource_OSVDB
21771
vdb-entry
x_refsource_OSVDB
256
third-party-advisory
x_refsource_SREASON
15865
vdb-entry
x_refsource_BID
15866
vdb-entry
x_refsource_BID
ADV-2005-2907
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now