Winace UUE File Handling Buffer Overflow Vulnerability
BID:27017
Info
Winace UUE File Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 27017 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6563 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 25 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | Fourteenforty Research Institute reported this vulnerability. |
| Vulnerable: |
Winace Winace 2.65 Winace Winace 2.60 |
| Not Vulnerable: |
Winace Winace 2.69 |
Discussion
Winace UUE File Handling Buffer Overflow Vulnerability
Winace is prone to a buffer-overflow vulnerability when handling malicious UUE files.
A successful attack can allow a remote attacker to corrupt process memory by triggering a heap-overflow condition when the application handles excessive data in the archive.
This vulnerability affects versions prior to Winace 2.69.
Winace is prone to a buffer-overflow vulnerability when handling malicious UUE files.
A successful attack can allow a remote attacker to corrupt process memory by triggering a heap-overflow condition when the application handles excessive data in the archive.
This vulnerability affects versions prior to Winace 2.69.
Exploit / POC
Winace UUE File Handling Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Winace UUE File Handling Buffer Overflow Vulnerability
Solution:
The vendor has released Winace 2.69 to address this issue.
Winace Winace 2.65
Winace Winace 2.60
Solution:
The vendor has released Winace 2.69 to address this issue.
Winace Winace 2.65
-
Winace Winace 2.69
http://www.winace.com/down.html
Winace Winace 2.60
-
Winace Winace 2.69
http://www.winace.com/down.html
References
Winace UUE File Handling Buffer Overflow Vulnerability
References:
References:
- Winace Homepage (Winace)
- [FFRRA-20071225] WinAce?uue (Fourteenforty Research Institute)
- JVN#44736880 (JPCERT/CC)