TUCoPS :: Web :: Apps :: tb10244.htm

SAP RFC_START_GUI RFC Function Buffer Overflow
CYBSEC Security Pre-Advisory: SAP RFC_START_GUI RFC Function Buffer Overflow
CYBSEC Security Pre-Advisory: SAP RFC_START_GUI RFC Function Buffer Overflow



This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig6B3BA1CDAA41E90F21F3C58B
Content-Type: multipart/mixed;
 boundary="------------010405050906050201070600"

This is a multi-part message in MIME format.
--------------010405050906050201070600
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable


(The following pre-advisory is also available in PDF format for download at:
http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_GUI_RFC_Function_Buffer_Overflow.pdf ) 


CYBSEC S.A.
www.cybsec.com 

Pre-Advisory Name: SAP RFC_START_GUI RFC Function Buffer Overflow
=================
Vulnerability Class: Buffer Overflow
===================
Release Date: 2007-04-03
============
Affected Applications:
======================2E SAP RFC Library 6.40
=2E SAP RFC Library 7.00

Affected Platforms:
==================
=2E AIX 32bit
=2E AIX 64bit
=2E HP-UX on IA64 64bit
=2E HP-UX on PA-RISC 64bit
=2E Linux on IA32 32bit
=2E Linux on IA64 64bit
=2E Linux on Power 64bit
=2E Linux on x86_64 64bit
=2E Linux on zSeries 64bit
=2E Mac OS
=2E OS/400
=2E OS/400 V5R2M0
=2E Reliant 32bit
=2E Solaris on SPARC 32bit
=2E Solaris on SPARC 64bit
=2E Solaris on x64_64 64bit
=2E TRU64 64bit
=2E Windows Server on IA32 32bit
=2E Windows Server on IA64 64bit
=2E Windows Server on x64 64bit
=2E z/OS 32bit

Local / Remote: Remote
==============
Severity: High
========
Author: Mariano Nu=F1ez Di Croce
======
Vendor Status: Confirmed. Updates Released.
=============
Reference to Vulnerability Disclosure Policy: http://www.cybsec.com/vulnerability_policy.pdf 
============================================
Product Overview:
================
"The RFC Library offers an interface to a SAP System. The RFC Library is the most commonly used and installed component of existing SAP Software. This
interface provides the opportunity to call any RFC Function in a SAP System from an external application. Moreover, the RFC Library offers the
possibility to write a RFC Server Program, which is accessible from any SAP System or external application. Most SAP Connectors use the RFC Library as
communication platform to SAP Systems."

RFC_START_GUI RFC Function is used to start SAPGUI on front-end systems. This function is installed by default in every external RFC server.

Vulnerability Description:
=========================
A remote buffer overflow vulnerability has been detected in the RFC_START_GUI RFC Function.

Technical Details:
=================
Technical details will be released three months after publication of this pre-advisory. This was agreed upon with SAP to allow their customers to
upgrade affected software prior to technical knowledge been publicly available.

Impact:
======
This vulnerability may allow an attacker to remotely execute arbitrary commands over external RFC servers.

Solutions:
=========
SAP has released patches to address this vulnerability. Affected customers should apply the patches immediately.
More information can be found on SAP Note 1003908.

Vendor Response:
===============
=2E 2006-11-21: Initial Vendor Contact.
=2E 2006-12-01: Vendor Confirmed Vulnerability.
=2E 2006-12-11: Vendor Releases Update for version 6.40.
=2E 2006-12-11: Vendor Releases Update for version 7.00.
=2E 2007-04-03: Pre-Advisory Public Disclosure.


Special Thanks:
==============
Thanks goes to Victor Montero and Gustavo Kunst.

Contact Information:
===================For more information regarding the vulnerability feel free to contact the author at mnunez  cybsec  com.



About  CYBSEC S.A. Security Systems
-----------------------------------

Since 1996 CYBSEC S.A. is devoted exclusively to provide professional services specialized in Computer Security. More than 150 clients around the
globe validate our quality and professionalism.
To keep objectivity, CYBSEC S.A. does not represent, neither sell, nor is associated with other software and/or hardware provider companies.
Our services are strictly focused on Information Security, protecting our clients from emerging security threats, mantaining their IT deployments
available, safe, and reliable.
Beyond professional services, CYBSEC is continuosly researching new defense and attack techiniques and contributing with the security community with
high quality information exchange.
=09
For more information, please visit www.cybsec.com 





--------------010405050906050201070600
Content-Type: application/pgp-signature;
 name="signature.asc"
Content-Transfer-Encoding: base64
Content-Disposition: inline;
 filename="signature.asc"

LS0tLS1CRUdJTiBQR1AgU0lHTkFUVVJFLS0tLS0KVmVyc2lvbjogR251UEcgdjEuNC42IChH
TlUvTGludXgpCgppRDhEQlFGR0U1NFJ2V1Bld3ZtZHJTZ1JBaDhpQUo5OWdwWTdXdjNMZks0
WC9nb1JsdG1Da0VaRVFBQ2VKQXhNCmtRcWJKbUxuZGxnRFNwMEdneW5lVXA4PQo9bHY5awot
LS0tLUVORCBQR1AgU0lHTkFUVVJFLS0tLS0KCg=--------------010405050906050201070600--

--------------enig6B3BA1CDAA41E90F21F3C58B
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGE552vWPewvmdrSgRAoRpAKCVQ17bv2WPKFQp0sEbdx6J0sGqjwCbBcA4
nbHdV3monj6CqlHKfrdL60k=Gu/Q
-----END PGP SIGNATURE-----

--------------enig6B3BA1CDAA41E90F21F3C58B--

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH