Microsoft Windows CHM File Processing Buffer Overflow Vulnerability
BID:33204
Info
Microsoft Windows CHM File Processing Buffer Overflow Vulnerability
| Bugtraq ID: | 33204 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2009 12:00AM |
| Updated: | Jan 12 2009 04:12PM |
| Credit: | securfrog |
| Vulnerable: |
Microsoft Windows XP Professional SP3 |
| Not Vulnerable: | |
Discussion
Microsoft Windows CHM File Processing Buffer Overflow Vulnerability
Microsoft Windows is prone to a buffer-overflow vulnerability because of an issue when processing CHM files.
Successfully exploiting this issue would allow attackers to corrupt memory and crash the application associated with these files. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
Windows XP Service Pack 3 is vulnerable; other versions may also be affected.
Microsoft Windows is prone to a buffer-overflow vulnerability because of an issue when processing CHM files.
Successfully exploiting this issue would allow attackers to corrupt memory and crash the application associated with these files. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
Windows XP Service Pack 3 is vulnerable; other versions may also be affected.
Exploit / POC
Microsoft Windows CHM File Processing Buffer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Microsoft Windows CHM File Processing Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Windows CHM File Processing Buffer Overflow Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)