ASP2PHP Preparse Temp Variable Buffer Overflow Vulnerability
BID:12015
Info
ASP2PHP Preparse Temp Variable Buffer Overflow Vulnerability
| Bugtraq ID: | 12015 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Discovery is credited to Qiao Zhang. |
| Vulnerable: |
asp2php asp2php 0.76.23 |
| Not Vulnerable: | |
Discussion
ASP2PHP Preparse Temp Variable Buffer Overflow Vulnerability
asp2php is prone to a buffer overflow vulnerability. This issue is exposed when the application is used to convert an ASP file to PHP. The particular issue is related to parsing of tokens in ASP files. Since ASP files may originate from an external or untrusted source, this vulnerability is considered to be remote in nature.
Successful exploitation would allow for execution of arbitrary code in the context of the user running the application.
This issue is reportedly distinct from BID 12014 (ASP2PHP Preparse Token Buffer Overflow Vulnerability). The differences that distinguish these issues are two separate vulnerabilities have not been determined at this time, other than that the overrun occurs in a different destination buffer.
asp2php is prone to a buffer overflow vulnerability. This issue is exposed when the application is used to convert an ASP file to PHP. The particular issue is related to parsing of tokens in ASP files. Since ASP files may originate from an external or untrusted source, this vulnerability is considered to be remote in nature.
Successful exploitation would allow for execution of arbitrary code in the context of the user running the application.
This issue is reportedly distinct from BID 12014 (ASP2PHP Preparse Token Buffer Overflow Vulnerability). The differences that distinguish these issues are two separate vulnerabilities have not been determined at this time, other than that the overrun occurs in a different destination buffer.
Exploit / POC
ASP2PHP Preparse Temp Variable Buffer Overflow Vulnerability
The following exploit example has been published:
The following exploit example has been published:
Solution / Fix
ASP2PHP Preparse Temp Variable Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ASP2PHP Preparse Temp Variable Buffer Overflow Vulnerability
References:
References:
- [remote] [control] asp2php 0.76.23 preparse() overflows token buffer; preparse() ("D. J. Bernstein"
) - asp2php Homepage (asp2php)