StackDefender ObjectAttributes Invalid Pointer Dereference Denial Of Service Vulnerability
BID:10849
Info
StackDefender ObjectAttributes Invalid Pointer Dereference Denial Of Service Vulnerability
| Bugtraq ID: | 10849 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0767 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 04 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited iDEFENSE. |
| Vulnerable: |
Next Generation Security Technologies StackDefender 1.10 |
| Not Vulnerable: |
Next Generation Security Technologies StackDefender 2.10 |
Discussion
StackDefender ObjectAttributes Invalid Pointer Dereference Denial Of Service Vulnerability
StackDefender is prone to a vulnerability that may permit attackers to crash the computer. This issue may be triggered if the program attempts to dereference an invalid pointer.
To exploit this issue, the attacker must be able to cause memory corruption on the host computer, such as through exploitation of buffer overflow in another application. This will force the software to attempt to block attempts to exploit the memory corruption vulnerability and in turn expose this vulnerability.
This issue is known to affect StackDefender 1.10.
StackDefender is prone to a vulnerability that may permit attackers to crash the computer. This issue may be triggered if the program attempts to dereference an invalid pointer.
To exploit this issue, the attacker must be able to cause memory corruption on the host computer, such as through exploitation of buffer overflow in another application. This will force the software to attempt to block attempts to exploit the memory corruption vulnerability and in turn expose this vulnerability.
This issue is known to affect StackDefender 1.10.
Exploit / POC
StackDefender ObjectAttributes Invalid Pointer Dereference Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
StackDefender ObjectAttributes Invalid Pointer Dereference Denial Of Service Vulnerability
Solution:
This issue has been addressed with the release of StackDefender 2.10. Users are advised to upgrade.
Next Generation Security Technologies StackDefender 1.10
Solution:
This issue has been addressed with the release of StackDefender 2.10. Users are advised to upgrade.
Next Generation Security Technologies StackDefender 1.10
-
Next Generation Security Technologies StackDefender-2.10.exe
http://www.ngsec.com/downloads/stackdefender/StackDefender-2.10.exe
References
StackDefender ObjectAttributes Invalid Pointer Dereference Denial Of Service Vulnerability
References:
References:
- NGSEC StackDefender 1.10 Invalid Pointer Dereference Vulnerability (iDEFENSE)
- StackDefender Homepage (Next Generation Security Technologies)