Home > Storage Technology News > Flaws reported in Trend Micro ServerProtect
Storage Technology News:
EMAIL THIS

Flaws reported in Trend Micro ServerProtect

By Bill Brenner, News Writer
15 Dec 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Attackers could exploit security holes in Trend Micro Inc.'s ServerProtect line to cause a denial-of-service or run malicious code, the iDefense division of Mountain View, Calif.-based VeriSign Inc. warned in a series of advisories.

ServerProtect provides comprehensive antivirus scanning for servers, detecting and removing viruses from typical and compressed files in real time before they reach the user, Trend Micro says on its Web site. The Tokyo-based vendor adds that "administrators can use a Windows-based console for centralized management of virus outbreaks, virus scanning, virus pattern file updates, notifications, and remote installation."

In addition to Trend Micro's ServerProtect product for Microsoft Windows/Novell Netware, there are also version for Linux systems, Network Appliance Inc. filters and for EMC Corp.'s Celerra file servers.
More on Trend Micro

Review: InterScan Web Security Suite easy to use and intuitive

Cisco, Trend Micro launch new service

Security hole in multiple Trend Micro products

Trend Micro: Virus damages reach $55 billion

According to iDefense, the security holes are:

A denial-of-service vulnerability in the EarthAgent daemon. By exploiting this, attackers could cause the target process to consume 100% of available [central processing unit] CPU resources, iDefense said, adding, "The problem specifically exists within ServerProtect EarthAgent in the handling of maliciously crafted packets transmitted with the magic value 'x21x43x65x87' targeting TCP port 5005. A memory leak also occurs with each received exploit packet, allowing an attacker to exhaust all available memory resources with repeated attack."

Trend Micro has issued a hotfix that it says "prevents the information server's CPU usage from increasing when responding to the malicious command."

As a workaround, iDefense recommends users "employ firewalls, access control lists or other TCP/UDP restriction mechanisms to limit access to vulnerable systems on TCP port 5005."

A heap overflow flaw in the ServerProtect Management Console. Remote attackers could launch malicious code with the privileges of the underlying Web server by exploiting a problem within the relay.dll ISAPI application when large POST requests are processed with "wrapped" length values.

Another Management Console flaw allows remote attackers to do the same type of damage. "The problem specifically exists within the isaNVWRequest.dll ISAPI application upon processing of large POST requests with 'wrapped' length values," iDefense said.

The Management Console also suffers from an input validation vulnerability. Attackers could exploit this to view the contents of arbitrary files on the underlying system. "The problem specifically exists within the handling of the IMAGE parameter in the script rptserver.asp," iDefense said. "An attacker can utilize directory traversal modifiers to traverse outside the system temporary directory and access any file on the same volume."

Trend Micro said its products will eventually be updated, sealing the security holes in the process. For now, iDefense said users can mitigate the Management Console threats by employing firewalls and accessing control lists or other TCP/UDP restriction mechanisms "to limit access to the vulnerable system on the configured port, generally TCP port 80."

Tags: SAN managementVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
SAN management
Unilever maintains 5 PB Fibre Channel SAN storage performance with Virtual Instruments' NetWisdom
Storage Decisions Chicago 2009 Session Downloads
Storage Decisions Session Downloads: Managing Storage Networks Track (Chicago 2009)
Storage-area networks to become increasingly object based
Data storage management in virtual server environments
10 Gb Ethernet bodes well for iSCSI
Mellanox builds bridge to consolidation
Best storage Products of the Year 2008
Wide stripe before you dive into SSD
How your SAN will evolve
SAN management Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Fast Guide to Storage Technologies  (WhatIs.com)
fat provisioning  (SearchStorage.com)
oversubscription  (SearchStorage.com)
RAID  (SearchStorage.com)
storage area management  (SearchStorage.com)
storage area network  (SearchStorage.com)
thin provisioning  (SearchStorage.com)
unified storage  (SearchStorage.com)
virtual provisioning  (SearchStorage.com)
zoned-bit recording  (SearchStorage.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Backup Solution Directory
TechTarget Storage Media
Storage Magazine View this month\\'s issue and subscribe today.
Storage Decisions Apply online for free conference admission.
SearchStorage.com
HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts