CVE-2007-2508: Buffer Overflow
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1) TCP port 5168, which triggers an overflow in the CAgRpcClient::CreateBinding function in the AgRpcCln.dll library in SpntSvc.exe; or (2) TCP port 3628, which triggers an overflow in EarthAgent.exe. NOTE: both issues are reachable via TmRpcSrv.dll.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2508?
CVE-2007-2508 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2007-2508?
You can fix CVE-2007-2508 by applying Security Patch 2 Build 1174 or later for Trend Micro ServerProtect 5.58.
Which versions of Trend Micro ServerProtect are affected by CVE-2007-2508?
CVE-2007-2508 affects Trend Micro ServerProtect versions prior to Security Patch 2 Build 1174.
What type of attack can exploit CVE-2007-2508?
CVE-2007-2508 can be exploited by sending crafted data to TCP port 5168, resulting in stack-based buffer overflows.
Is there a way to mitigate CVE-2007-2508 if I cannot apply the patch?
If you cannot apply the patch for CVE-2007-2508, consider restricting access to TCP port 5168 as a temporary mitigation.