WinUAE 'zfile.c' Stack-Based Buffer Overflow Vulnerability
BID:26979
Info
WinUAE 'zfile.c' Stack-Based Buffer Overflow Vulnerability
| Bugtraq ID: | 26979 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6537 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 21 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | Luigi Auriemma is credited with the discovery of this issue. |
| Vulnerable: |
WinUAE WinUAE 1.4.4 |
| Not Vulnerable: |
WinUAE WinUAE 1.4.5 |
Discussion
WinUAE 'zfile.c' Stack-Based Buffer Overflow Vulnerability
WinUAE is prone to a local stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
This issue affects versions prior to WinUAE 1.4.5.
WinUAE is prone to a local stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
This issue affects versions prior to WinUAE 1.4.5.
Exploit / POC
WinUAE 'zfile.c' Stack-Based Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
WinUAE 'zfile.c' Stack-Based Buffer Overflow Vulnerability
Solution:
The vendor released WinUAE 1.4.4 to address this issue. Please see the references for more information.
WinUAE WinUAE 1.4.4
Solution:
The vendor released WinUAE 1.4.4 to address this issue. Please see the references for more information.
WinUAE WinUAE 1.4.4
-
WinUAE WinUAE1450.zip
http://www.winuae.net/files/WinUAE1450.zip
References
WinUAE 'zfile.c' Stack-Based Buffer Overflow Vulnerability
References:
References:
- WinUAE Homepage (WinUAE)
- Buffer-overflow in WinUAE 1.4.4 (Luigi Auriemma
)