WildTangent WebDriver Remote Filename Buffer Overflow Vulnerability
BID:10421
Info
WildTangent WebDriver Remote Filename Buffer Overflow Vulnerability
| Bugtraq ID: | 10421 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2004 12:00AM |
| Updated: | Jan 29 2004 12:00AM |
| Credit: | Discovery is credited to Cesar Cerrudo. This issue was also independently discovered by Peter Winter-Smith of NGSSoftware. |
| Vulnerable: |
WildTangent WebDriver 4.0 |
| Not Vulnerable: |
WildTangent WebDriver 4.1 |
Discussion
WildTangent WebDriver Remote Filename Buffer Overflow Vulnerability
A remotely exploitable stack-based buffer overflow exists in WildTangent WebDriver.
This issue may be exploited through methods that take a filename as an argument and is known to occur in the WTHoster and WebDriver modules. The vulnerability can be exploited to execute arbitrary code in the context of the client user.
Exploitation will likely occur when the victim user visits a malicious web page that calls the vulnerable methods with excessive filename arguments.
This vulnerability was reported in WebDriver 4.0. Earlier versions may also be affected.
A remotely exploitable stack-based buffer overflow exists in WildTangent WebDriver.
This issue may be exploited through methods that take a filename as an argument and is known to occur in the WTHoster and WebDriver modules. The vulnerability can be exploited to execute arbitrary code in the context of the client user.
Exploitation will likely occur when the victim user visits a malicious web page that calls the vulnerable methods with excessive filename arguments.
This vulnerability was reported in WebDriver 4.0. Earlier versions may also be affected.
Exploit / POC
WildTangent WebDriver Remote Filename Buffer Overflow Vulnerability
The researchers who discovered this vulnerability have developed working exploit code that is not publicly available or known to be circulating in the wild.
The researchers who discovered this vulnerability have developed working exploit code that is not publicly available or known to be circulating in the wild.
Solution / Fix
WildTangent WebDriver Remote Filename Buffer Overflow Vulnerability
Solution:
This issue has reportedly been addressed in WebDriver 4.1.
WildTangent WebDriver 4.0
Solution:
This issue has reportedly been addressed in WebDriver 4.1.
WildTangent WebDriver 4.0
-
WildTangent WebDriver 4.1
http://www.wildtangent.com/default.asp?pageID=webdriver_download
References
WildTangent WebDriver Remote Filename Buffer Overflow Vulnerability
References:
References:
- WildTangent Homepage (WildTangent)
- WildTangent Web Driver Long FileName Stack Overflow (NGSSoftware)
- Re: WildTangent Web Driver Long FileName Stack Overflow (Cesar
)