HTML2HDML File Conversion Buffer Overflow Vulnerability
BID:12003
Info
HTML2HDML File Conversion Buffer Overflow Vulnerability
| Bugtraq ID: | 12003 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Discovery is credited to Wiktor Kopec and Matthew Dabrowski. |
| Vulnerable: |
html2hdml html2hdml 1.0.3 |
| Not Vulnerable: | |
Discussion
HTML2HDML File Conversion Buffer Overflow Vulnerability
html2hdml is prone to a buffer overflow vulnerability. This issue is exposed when converting HTML files to HDML (Handheld Device Markup Language). Since HTML files may originate from an external or untrusted source, this vulnerability is considered remote in nature.
Successful exploitation may result in execution of arbitrary code in the context of the user running the application.
html2hdml is prone to a buffer overflow vulnerability. This issue is exposed when converting HTML files to HDML (Handheld Device Markup Language). Since HTML files may originate from an external or untrusted source, this vulnerability is considered remote in nature.
Successful exploitation may result in execution of arbitrary code in the context of the user running the application.
Exploit / POC
HTML2HDML File Conversion Buffer Overflow Vulnerability
The following exploit example has been published:
The following exploit example has been published:
Solution / Fix
HTML2HDML File Conversion Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
HTML2HDML File Conversion Buffer Overflow Vulnerability
References:
References:
- [remote] [control] html2hdml 1.0.3 remove_quote overflows print_buf buffer ("D. J. Bernstein"
) - html2hdml Homepage (html2hdml)