ooVoo URI Handler Remote Buffer Overflow Vulnerability
BID:32251
Info
ooVoo URI Handler Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 32251 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6953 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2008 12:00AM |
| Updated: | Apr 16 2015 05:51PM |
| Credit: | Nine:Situations:Group::bruiser |
| Vulnerable: |
ooVoo ooVoo 1.7.1 35 ooVoo ooVoo 1.7.1.57 |
| Not Vulnerable: |
ooVoo ooVoo 1.7.1.59 |
Discussion
ooVoo URI Handler Remote Buffer Overflow Vulnerability
ooVoo is prone to a remote buffer-overflow vulnerability because it fails to perform adequate checks on user-supplied input.
A remote attacker may exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts may cause denial-of-service conditions.
ooVoo 1.7.1.35 is vulnerable; other versions may also be affected.
ooVoo is prone to a remote buffer-overflow vulnerability because it fails to perform adequate checks on user-supplied input.
A remote attacker may exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts may cause denial-of-service conditions.
ooVoo 1.7.1.35 is vulnerable; other versions may also be affected.
Exploit / POC
ooVoo URI Handler Remote Buffer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
ooVoo URI Handler Remote Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
Vendor updates are available. Contact the vendor for details on obtaining and applying the appropriate updates.
References
ooVoo URI Handler Remote Buffer Overflow Vulnerability
References:
References: