关键信息 EED-ID: 18765 CVEs: CVE-2012-4335, CVE-2012-4334, CVE-2012-4333, CVE-2012-4330, CVE-2012-4329 Author: Luigi Auriemma Type: DOS Platform: Windows Date: 2012-04-22 Vulnerability Details: Application: Samsung NET-i ware Application Downloads: - http://www.samsungsecurity.com/product/product_view.asp?idx=6447 - http://www.samsungsecurity.com/product/product_view.asp?idx=5828 Affected Versions: <= 1.37 Platform: Windows Bugs: - A] Endless loop in remote services - All the NET-i ware services are affected by an endless loop caused by the wrong handling of negative 32-bit size fields. - B] Code execution in ConnectDDNS ActiveX - ActiveX components affected: EEDBA32E-5C2D-48f1-A58E-0AAB0BC230ES, 17A7F731-C9EC-461C-8813-2F42A1BB58EB - The bug is not much reliable to replicate, so it is reported just for reference. - C] Stack overflow in BackupToAvi ActiveX - ActiveX components affected: 3D6F2DBA-F4E5-40A6-8725-E99BC96CC23A, 208650B1-3CA1-4406-926D-45F2DBB9C299 Exploits: A] Endless Loop: - http://aluigi.org/testz/udpsz.zip - https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18112.zip B, C] Code Execution and Stack Overflow: - http://aluigi.org/poc/netiware_1b.zip Fix: No fix mentioned.