XLReader Remote Client-Side Buffer Overflow Vulnerability
BID:11970
Info
XLReader Remote Client-Side Buffer Overflow Vulnerability
| Bugtraq ID: | 11970 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2004 12:00AM |
| Updated: | Dec 16 2004 12:00AM |
| Credit: | Tom Palarz and Kris Kubicki are credited with the discovery of this issue. |
| Vulnerable: |
xlreader xlreader 0.9 |
| Not Vulnerable: | |
Discussion
XLReader Remote Client-Side Buffer Overflow Vulnerability
A remote, client-side buffer overflow vulnerability affects xlreader. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
A remote, client-side buffer overflow vulnerability affects xlreader. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
XLReader Remote Client-Side Buffer Overflow Vulnerability
The following proof of concept exploit has been made available. Reportedly, when parsed by the affected application, creates a file titled 'EXPLOITED' in the current working directory. This proof of concept has not been verified by Symantec.
The following proof of concept exploit has been made available. Reportedly, when parsed by the affected application, creates a file titled 'EXPLOITED' in the current working directory. This proof of concept has not been verified by Symantec.
Solution / Fix
XLReader Remote Client-Side Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
XLReader Remote Client-Side Buffer Overflow Vulnerability
References:
References:
- [remote] [control] xlreader 0.9.0 overflows insert_start buffer ("D. J. Bernstein"
) - xlreader Home Page (xlreader)