Panzura Security Advisory PZOS-2013-001
|Title:||PZOS RPC Buffer Overflow|
|Affected Products:||PZOS 220.127.116.11.5075.E or Below|
A vulnerability in the RPC (remote procedure call) implementation on the Panzura PZOS version 18.104.22.168.5075.E or below has been discovered. This vulnerability can result in a buffer overflow that may allow an unauthorized user to execute arbitrary code via a structured RPC request.
A buffer overflow condition can exist in the PZOS execution of remote procedure calls. By sending a specifically constructed packet, an unauthenticated remote attacker could cause a denial of service or arbitrary code execution with elevated system privileges.
An exploit (none known to exist at this time) of this vulnerability could result in unauthorized access or data modification, disruption of service, or disabling the appliance.
Upgrade the Panzura software to PZOS version 22.214.171.124 or higher; any future major or minor releases will also correct the issue. Release notes for this version will outline details as necessary for this correction.