BreakPoint Software Hex Workshop '.hex' File Handling Buffer Overflow Vulnerability
BID:33932
Info
BreakPoint Software Hex Workshop '.hex' File Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 33932 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0812 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2009 12:00AM |
| Updated: | Oct 23 2012 03:40PM |
| Credit: | DATA_SNIPER |
| Vulnerable: |
BreakPoint Software Hex Workshop 6.0.1 .4603 BreakPoint Software Hex Workshop 6.0 .4582 BreakPoint Software Hex Workshop 5.1.4 .4188 BreakPoint Software Hex Workshop 5.1.4 BreakPoint Software Hex Workshop 5.1.3 .4159 BreakPoint Software Hex Workshop 5.1.1 .3963 BreakPoint Software Hex Workshop 5.0.2 .2769 BreakPoint Software Hex Workshop 5.0.1 .272 BreakPoint Software Hex Workshop 5.0 .2511 BreakPoint Software Hex Workshop 6 BreakPoint Software Hex Workshop 5.0 beta 1 BreakPoint Software Hex Workshop 4.23 BreakPoint Software Hex Workshop 4.22 BreakPoint Software Hex Workshop 4.21 BreakPoint Software Hex Workshop 4.20 BreakPoint Software Hex Workshop 4.00 BreakPoint Software Hex Workshop 3.11 |
| Not Vulnerable: | |
Discussion
BreakPoint Software Hex Workshop '.hex' File Handling Buffer Overflow Vulnerability
Hex Workshop is prone to a buffer-overflow vulnerability because it fails to adequately validate user-supplied data before copying it into an insufficiently sized buffer.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Hex Workshop 3.11 through 6.0.1.4603 are vulnerable; other versions may also be affected.
Hex Workshop is prone to a buffer-overflow vulnerability because it fails to adequately validate user-supplied data before copying it into an insufficiently sized buffer.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Hex Workshop 3.11 through 6.0.1.4603 are vulnerable; other versions may also be affected.
Exploit / POC
BreakPoint Software Hex Workshop '.hex' File Handling Buffer Overflow Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
BreakPoint Software Hex Workshop '.hex' File Handling Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
BreakPoint Software Hex Workshop '.hex' File Handling Buffer Overflow Vulnerability
References:
References:
- Hex Workshop Homepage (BreakPoint Software)
- Hex Workshop <= v6 (.hex) File Local Code ([email protected])