ProWizard 4 PC Multiple Remote Stack Based Buffer Overflow Vulnerabilities
BID:26953
Info
ProWizard 4 PC Multiple Remote Stack Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 26953 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6510 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | Luigi Auriemma is credited with the discovery of these issues. |
| Vulnerable: |
ProWizard 4 PC ProWizard 4 PC 1.62 |
| Not Vulnerable: | |
Discussion
ProWizard 4 PC Multiple Remote Stack Based Buffer Overflow Vulnerabilities
ProWizard 4 PC is prone to multiple stack-based buffer-overflow issues because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
These issues affect ProWizard 4 PC 1.62 and prior versions; other versions may also be vulnerable.
ProWizard 4 PC is prone to multiple stack-based buffer-overflow issues because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
These issues affect ProWizard 4 PC 1.62 and prior versions; other versions may also be vulnerable.
Exploit / POC
ProWizard 4 PC Multiple Remote Stack Based Buffer Overflow Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to open a malicious file.
The following proof-of-concept code is available:
To exploit these issues, an attacker must entice an unsuspecting user to open a malicious file.
The following proof-of-concept code is available:
Solution / Fix
ProWizard 4 PC Multiple Remote Stack Based Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ProWizard 4 PC Multiple Remote Stack Based Buffer Overflow Vulnerabilities
References:
References:
- ProWizard 4 PC (ProWizard 4 PC)
- Some buffer-overflow in ProWizard 1.62 (Luigi Auriemma)