Google Earth KML/KMZ Files Buffer Overflow Vulnerability
BID:20464
Info
Google Earth KML/KMZ Files Buffer Overflow Vulnerability
| Bugtraq ID: | 20464 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-7157 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | The JAAScois Security Team disclosed this issue. |
| Vulnerable: |
Google Google Earth (beta) 4.0.2091(beta) |
| Not Vulnerable: | |
Discussion
Google Earth KML/KMZ Files Buffer Overflow Vulnerability
Google Earth is prone to a buffer-overflow vulnerability because the application to properly verify the size of user-supplied data before copying it into an insufficiently sized process buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of the user running the affected application. Failed exploit attempts will likely crash applications, denying service to legitimate users.
Google Earth version v4.0.2091(beta) is vulnerable to this issue.
Google Earth is prone to a buffer-overflow vulnerability because the application to properly verify the size of user-supplied data before copying it into an insufficiently sized process buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of the user running the affected application. Failed exploit attempts will likely crash applications, denying service to legitimate users.
Google Earth version v4.0.2091(beta) is vulnerable to this issue.
Exploit / POC
Google Earth KML/KMZ Files Buffer Overflow Vulnerability
An exploit written in C has been provided:
An exploit written in C has been provided:
Solution / Fix
Google Earth KML/KMZ Files Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any solutions for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any solutions for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].