ABC2MIDI Multiple Stack Buffer Overflow Vulnerabilities
BID:12019
Info
ABC2MIDI Multiple Stack Buffer Overflow Vulnerabilities
| Bugtraq ID: | 12019 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Limin Wang discovered these vulnerabilities. |
| Vulnerable: |
abcMIDI abcMIDI 2004-12-04 |
| Not Vulnerable: | |
Discussion
ABC2MIDI Multiple Stack Buffer Overflow Vulnerabilities
It is reported that abc2midi is susceptible to two stack buffer overflow vulnerabilities. These issues are due to a failure of the application to properly bounds check user-supplied image data prior to copying it into fixed-size memory buffers.
These vulnerabilities allow remote attackers to alter the proper flow of execution of the application, potentially resulting in the execution of attacker-supplied machine code in the context of the application attempting to read malicious ABC files.
It is reported that abc2midi is susceptible to two stack buffer overflow vulnerabilities. These issues are due to a failure of the application to properly bounds check user-supplied image data prior to copying it into fixed-size memory buffers.
These vulnerabilities allow remote attackers to alter the proper flow of execution of the application, potentially resulting in the execution of attacker-supplied machine code in the context of the application attempting to read malicious ABC files.
Exploit / POC
ABC2MIDI Multiple Stack Buffer Overflow Vulnerabilities
Proof of concept ABC files sufficient to exploit this vulnerability have been provided:
Proof of concept ABC files sufficient to exploit this vulnerability have been provided:
Solution / Fix
ABC2MIDI Multiple Stack Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ABC2MIDI Multiple Stack Buffer Overflow Vulnerabilities
References:
References:
- [remote] [control] abc2midi 2004.12.04 event_text overflows msg buffer; event_sp ("D. J. Bernstein"
) - abcMIDI Home Page (abcMIDI)