AOH :: HP Unsorted A :: BX2323.HTM

Acronis True Image Windows Agent 1.0.0.54 null pointer vuln



NULL pointer in Acronis True Image Windows Agent 1.0.0.54
NULL pointer in Acronis True Image Windows Agent 1.0.0.54




#######################################################################

                             Luigi Auriemma

Application:  Acronis True Image Windows Agent
http://www.acronis.com/enterprise/products/ATIES/windows-agent.html 
Versions:     <= 1.0.0.54
              (included in Acronis True Image Enterprise Server
              9.5.0.8072 and the other True Image packages)
Platforms:    Windows
              Linux is not affected
Bug:          NULL pointer
Exploitation: remote
Date:         08 Mar 2008
Author:       Luigi Auriemma
e-mail: aluigi@autistici.org 
              web:    aluigi.org


#######################################################################


1) Introduction
2) Bug
3) The Code
4) Fix


#######################################################################

==============1) Introduction
==============

The Acronis Agent is an essential component of Acronis True Image Echo
Server (Workstation and Enterprise packages) and is a server running on
the TCP and UDP port 9876 which allows the local and remote management
of Acronis TrueImage.

The Acronis True Image Windows Agent must be not confused with the
Acronis Snap Deploy Management Agent which uses the same ports but a
different protocol and so it's not affected by this bug.


#######################################################################

=====2) Bug
=====

A NULL pointer vulnerability can be exploited through the sending of a
malformed packet to the server causing its immediate termination.


#######################################################################

==========3) The Code
==========

http://aluigi.org/poc/acroagent.txt 

  nc SERVER 9876 -v -v < acroagent.txt


#######################################################################

=====4) Fix
=====

No fix


#######################################################################


--- 
Luigi Auriemma
http://aluigi.org 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.