Description
NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by pasting a 1000-byte buffer into the Share Name parameter when adding a new share through the Manage Shares interface.
Problem types
Product status
Credits
Alejandra Sánchez
References
www.exploit-db.com/exploits/46909 (ExploitDB-46909)
www.infiltration-systems.com (Official Product Homepage)
www.vulncheck.com/...s/netaware-share-name-denial-of-service (VulnCheck Advisory: NetAware 1.20 Share Name Denial of Service)