BigAnt Server SCH request Buffer Overflow

Strike ID:
E13-ptk01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2013

Description

This strike identifies a vulnerability in BigAnt Server. SCH and DUPF requests are not properly validated, and when an overly long value is passed to the username value in an SCH request, an SQL query fails. This error message is copied to a 400 byte stack buffer without validation.

CVE

Bid