CVE Database
/

CVE-2006-3838

Back to search

CVE-2006-3838

Published: Jul 27, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer Network Security Analyzer, and possibly other products, allow remote attackers to execute arbitrary code via long (1) DELTAINTERVAL, (2) LOGFOLDER, (3) DELETELOGS, (4) FWASERVER, (5) SYSLOGPUBLICIP, (6) GETFWAIMPORTLOG, (7) GETFWADELTA, (8) DELETERDEPDEVICE, (9) COMPRESSRAWLOGFILE, (10) GETSYSLOGFIREWALLS, (11) ADDPOLICY, and (12) EDITPOLICY commands to the Syslog daemon (syslogserver.exe); (13) GUIADDDEVICE, (14) ADDDEVICE, and (15) DELETEDEVICE commands to the Topology server (Topology.exe); the (15) LICMGR_ADDLICENSE command to the License Manager (EnterpriseSecurityAnalyzer.exe); the (16) TRACE and (17) QUERYMONITOR commands to the Monitoring agent (Monitoring.exe); and possibly other vectors related to the Syslog daemon (syslogserver.exe).

VendorProductVersions

n/a

n/a

affected
n/a

References

19167
vdb-entry
x_refsource_BID
21218
third-party-advisory
x_refsource_SECUNIA
ADV-2006-3007
vdb-entry
x_refsource_VUPEN
27526
vdb-entry
x_refsource_OSVDB
21217
third-party-advisory
x_refsource_SECUNIA
27527
vdb-entry
x_refsource_OSVDB
1016580
vdb-entry
x_refsource_SECTRACK
19163
vdb-entry
x_refsource_BID
ADV-2006-2985
vdb-entry
x_refsource_VUPEN
21215
third-party-advisory
x_refsource_SECUNIA
ADV-2006-3008
vdb-entry
x_refsource_VUPEN
eiqnetworks-esa-topology-bo(27953)
vdb-entry
x_refsource_XF
27528
vdb-entry
x_refsource_OSVDB
21211
third-party-advisory
x_refsource_SECUNIA
19164
vdb-entry
x_refsource_BID
VU#513068
third-party-advisory
x_refsource_CERT-VN
ADV-2006-3006
vdb-entry
x_refsource_VUPEN
21214
third-party-advisory
x_refsource_SECUNIA
19165
vdb-entry
x_refsource_BID
27525
vdb-entry
x_refsource_OSVDB
ADV-2006-3010
vdb-entry
x_refsource_VUPEN
21213
third-party-advisory
x_refsource_SECUNIA
ADV-2006-3009
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now