Sysinternals Process Explorer CompanyName Value Buffer Overflow Vulnerability
BID:14616
Info
Sysinternals Process Explorer CompanyName Value Buffer Overflow Vulnerability
| Bugtraq ID: | 14616 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2679 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 20 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | ATmaCA <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Sysinternals Process Explorer 9.23 |
| Not Vulnerable: |
Sysinternals Process Explorer 9.25 |
Discussion
Sysinternals Process Explorer CompanyName Value Buffer Overflow Vulnerability
Process Explorer is prone to a buffer overflow vulnerability. This issue is due to a failure in the application to perform proper bounds checking on user-supplied data.
A successful attack can result in the overflowing of a finite sized buffer and may ultimately lead to the execution of arbitrary code in the context of the affected application.
Process Explorer is prone to a buffer overflow vulnerability. This issue is due to a failure in the application to perform proper bounds checking on user-supplied data.
A successful attack can result in the overflowing of a finite sized buffer and may ultimately lead to the execution of arbitrary code in the context of the affected application.
Exploit / POC
Sysinternals Process Explorer CompanyName Value Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
A proof of concept exploit is available at the following location:
http://www.atmacasoft.com/procexp_exp.exe
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
A proof of concept exploit is available at the following location:
http://www.atmacasoft.com/procexp_exp.exe
Solution / Fix
Sysinternals Process Explorer CompanyName Value Buffer Overflow Vulnerability
Solution:
The vendor has addressed this issue in Process Explorer 9.25.
Sysinternals Process Explorer 9.23
Solution:
The vendor has addressed this issue in Process Explorer 9.25.
Sysinternals Process Explorer 9.23
-
Sysinternals ProcessExplorer9x.zip
For Win9x/Me.
http://www.sysinternals.com/Files/ProcessExplorer9x.zip -
Sysinternals ProcessExplorerAmd64.zip
For 64-bit XP/Server 2003.
http://www.sysinternals.com/Files/ProcessExplorerAmd64.zip -
Sysinternals ProcessExplorerNt.zip
For NT/2K/XP/Server 2003.
http://www.sysinternals.com/Files/ProcessExplorerNt.zip
References
Sysinternals Process Explorer CompanyName Value Buffer Overflow Vulnerability
References:
References:
- Process Explorer Homepage (Sysinternals)
- Vendor Home Page (Sysinternals)