PC SOFT WinDEV WDP File Parsing Stack Buffer Overflow Vulnerability
BID:24693
Info
PC SOFT WinDEV WDP File Parsing Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 24693 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3479 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Jerome Athias is credited with discovering this issue. |
| Vulnerable: |
PC SOFT Windev 11 |
| Not Vulnerable: | |
Discussion
PC SOFT WinDEV WDP File Parsing Stack Buffer Overflow Vulnerability
PC SOFT WinDEV is prone to a stack-based buffer-overflow vulnerability when it attempts to process malformed project files. This issue occurs because the application fails to perform proper bounds-checking on user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user running the vulnerable application or to cause denial-of-service conditions. This may facilitate unauthorized access or privilege escalation.
PC SOFT WinDEV 11 is reported vulnerable; other versions and related products (WinDEV Express, Mobile, and WebDEV) may also be affected.
PC SOFT WinDEV is prone to a stack-based buffer-overflow vulnerability when it attempts to process malformed project files. This issue occurs because the application fails to perform proper bounds-checking on user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user running the vulnerable application or to cause denial-of-service conditions. This may facilitate unauthorized access or privilege escalation.
PC SOFT WinDEV 11 is reported vulnerable; other versions and related products (WinDEV Express, Mobile, and WebDEV) may also be affected.
Exploit / POC
PC SOFT WinDEV WDP File Parsing Stack Buffer Overflow Vulnerability
The following proofs of concept are available:
The following proofs of concept are available:
Solution / Fix
PC SOFT WinDEV WDP File Parsing Stack Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PC SOFT WinDEV WDP File Parsing Stack Buffer Overflow Vulnerability
References:
References:
- [SecurInfos] PCSoft WinDEV .wdp Project File Handling Buffer Overflow ( Jerome Athias)
- PCSoft Homepage (PCSoft)