Winace Malformed Filename Remote Denial of Service Vulnerability
BID:33049
Info
Winace Malformed Filename Remote Denial of Service Vulnerability
| Bugtraq ID: | 33049 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2008 12:00AM |
| Updated: | Jan 02 2009 05:21PM |
| Credit: | Cn4phux |
| Vulnerable: |
Winace Winace 2.2 |
| Not Vulnerable: | |
Discussion
Winace Malformed Filename Remote Denial of Service Vulnerability
Winace is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to crash Windows Explorer, denying service to legitimate users. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
Winace 2.2 is vulnerable; other versions may also be affected.
Winace is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to crash Windows Explorer, denying service to legitimate users. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
Winace 2.2 is vulnerable; other versions may also be affected.
Exploit / POC
Winace Malformed Filename Remote Denial of Service Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to download a malicious file and compress it through Windows Explorer.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to download a malicious file and compress it through Windows Explorer.
The following exploit code is available:
Solution / Fix
Winace Malformed Filename Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Winace Malformed Filename Remote Denial of Service Vulnerability
References:
References:
- Winace Homepage (Winace)