OllyDbg Debugger Messages Format String Vulnerability
BID:10742
Info
OllyDbg Debugger Messages Format String Vulnerability
| Bugtraq ID: | 10742 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0733 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2004 12:00AM |
| Updated: | Apr 17 2007 10:41PM |
| Credit: | Discovery is credited to ned <[email protected]>. |
| Vulnerable: |
OllyDbg OllyDbg 1.10 OllyDbg OllyDbg 1.0 9 OllyDbg OllyDbg 1.0 8b OllyDbg OllyDbg 1.0 6 |
| Not Vulnerable: | |
Discussion
OllyDbg Debugger Messages Format String Vulnerability
OllyDbg is prone to a format-string vulnerability.
This issue occurs when the application handles debugger messages that contain format specifiers.
Debugging a malicious program that is designed to exploit this issue could crash the application or allow arbitrary code to run in the context of the user running the debugger.
OllyDbg is prone to a format-string vulnerability.
This issue occurs when the application handles debugger messages that contain format specifiers.
Debugging a malicious program that is designed to exploit this issue could crash the application or allow arbitrary code to run in the context of the user running the debugger.
Exploit / POC
OllyDbg Debugger Messages Format String Vulnerability
The following exploit was provided:
The following exploit was provided:
Solution / Fix
OllyDbg Debugger Messages Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
OllyDbg Debugger Messages Format String Vulnerability
References:
References:
- OllyDbg Homepage (OllyDbg)
- [FMADV] Format String Bug in OllyDbg 1.10 (ned
)