POP Peeper 'Date' Remote Buffer Overflow Vulnerability
BID:34093
Info
POP Peeper 'Date' Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 34093 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2009 12:00AM |
| Updated: | Mar 13 2009 05:26PM |
| Credit: | Jeremy Brown |
| Vulnerable: |
Mortal Universe Software Entertainment POP Peeper 3.4 .0 |
| Not Vulnerable: | |
Discussion
POP Peeper 'Date' Remote Buffer Overflow Vulnerability
POP Peeper is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
POP Peeper 3.4.0.0 is vulnerable; other versions may also be affected.
POP Peeper is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
POP Peeper 3.4.0.0 is vulnerable; other versions may also be affected.
Exploit / POC
POP Peeper 'Date' Remote Buffer Overflow Vulnerability
An attacker may exploit this issue by enticing a victim into connecting to a malicious server.
The following exploit is available:
An attacker may exploit this issue by enticing a victim into connecting to a malicious server.
The following exploit is available:
Solution / Fix
POP Peeper 'Date' Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
POP Peeper 'Date' Remote Buffer Overflow Vulnerability
References:
References:
- POP Peeper 3.4.0.0 Date Remote Buffer Overflow Vulnerability (Krakow Labs Research)
- POP Peeper 3.4.0.0 Date Remote Buffer Overflow Vulnerability (Krakow Labs)
- POP Peeper Homepage (POP Peeper)
- POP Peeper 3.4.0.0 Date Remote Buffer Overflow Vulnerability (Krakow Labs
)