Massimiliano Montoro Cain & Abel Malformed '.conf' File Buffer Overflow Vulnerability
BID:33142
Info
Massimiliano Montoro Cain & Abel Malformed '.conf' File Buffer Overflow Vulnerability
| Bugtraq ID: | 33142 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2009 12:00AM |
| Updated: | Jan 08 2009 04:12PM |
| Credit: | send9 |
| Vulnerable: |
Massimiliano Montoro Cain & Abel 4.9.25 |
| Not Vulnerable: |
Massimiliano Montoro Cain & Abel 4.9.26 |
Discussion
Massimiliano Montoro Cain & Abel Malformed '.conf' File Buffer Overflow Vulnerability
Cain & Abel is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects Cain & Abel 4.9.25; other versions may also be affected.
Cain & Abel is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects Cain & Abel 4.9.25; other versions may also be affected.
Exploit / POC
Massimiliano Montoro Cain & Abel Malformed '.conf' File Buffer Overflow Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
Massimiliano Montoro Cain & Abel Malformed '.conf' File Buffer Overflow Vulnerability
Solution:
The vendor has released an update to address the issue. Please see the references for more information.
Solution:
The vendor has released an update to address the issue. Please see the references for more information.
References
Massimiliano Montoro Cain & Abel Malformed '.conf' File Buffer Overflow Vulnerability
References:
References:
- Cain & Abel Homepage (Oxid.it)
- Cain & Abel v4.9.26 released (Massimiliano Montoro)