Unisys.Business.Information.Server

NameUnisys.Business.Information.Server.Stack.Buffer.Overflow
Last Updated DateAug 25, 2009
Release DateAug 18, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a buffer overflow vulnerability in Unisys Business Information Server.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted packet. It allows a remote attacker to execute arbitrary code.
Affected ProductsUnisys Business Information Server 10.1
Unisys Business Information Server 10
Recommended ActionsApply patch, available from the web site:
ftp://ftp.support.unisys.com/pub/mapper/NT/BIS10.1/Readme.txt
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1628
Reference/shttp://www.securityfocus.com/bid/35494 (BugTraq)
Reference: VID-17617