OpenSG 'OSGHDRImageFileType.cpp' Radiance RGBE File Stack Buffer Overflow Vulnerability
BID:33362
Info
OpenSG 'OSGHDRImageFileType.cpp' Radiance RGBE File Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 33362 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2009 12:00AM |
| Updated: | Jan 20 2009 11:42PM |
| Credit: | Stefan Cornelius, Secunia Research |
| Vulnerable: |
OpenSG OpenSG 1.8 |
| Not Vulnerable: | |
Discussion
OpenSG 'OSGHDRImageFileType.cpp' Radiance RGBE File Stack Buffer Overflow Vulnerability
OpenSG is prone to a stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data.
An attacker can exploit this issue to execute arbitrary machine code in the context of applications using the vulnerable library. Failed exploit attempts will likely cause denial-of-service conditions.
This issue affects OpenSG 1.8.0; other versions may also be affected.
OpenSG is prone to a stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data.
An attacker can exploit this issue to execute arbitrary machine code in the context of applications using the vulnerable library. Failed exploit attempts will likely cause denial-of-service conditions.
This issue affects OpenSG 1.8.0; other versions may also be affected.
Exploit / POC
OpenSG 'OSGHDRImageFileType.cpp' Radiance RGBE File Stack Buffer Overflow Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenSG 'OSGHDRImageFileType.cpp' Radiance RGBE File Stack Buffer Overflow Vulnerability
Solution:
The vendor has committed fixes to the project's CVS repository. Please see the references for more information.
Solution:
The vendor has committed fixes to the project's CVS repository. Please see the references for more information.
References
OpenSG 'OSGHDRImageFileType.cpp' Radiance RGBE File Stack Buffer Overflow Vulnerability
References:
References:
- OpenSG Homepage (OpenSG)
- Secunia Research: OpenSG Radiance RGBE Buffer Overflow Vulnerability (Secunia Research
) - Secunia Research: OpenSG Radiance RGBE Buffer Overflow Vulnerability (Secunia Research)