PowerISO Buffer Overflow Vulnerability
BID:36387
Info
PowerISO Buffer Overflow Vulnerability
| Bugtraq ID: | 36387 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2009 12:00AM |
| Updated: | Sep 17 2009 07:40PM |
| Credit: | Dr_IDE |
| Vulnerable: |
PowerISO PowerISO 4.0 |
| Not Vulnerable: |
PowerISO PowerISO 4.7 |
Discussion
PowerISO Buffer Overflow Vulnerability
PowerISO is prone a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
The issue occurs when handling specially crafted files.
Successful exploits allow remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
PowerISO 4.0 is affected; other versions may also be vulnerable.
PowerISO is prone a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
The issue occurs when handling specially crafted files.
Successful exploits allow remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
PowerISO 4.0 is affected; other versions may also be vulnerable.
Exploit / POC
PowerISO Buffer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
PowerISO Buffer Overflow Vulnerability
Solution:
Reportedly, the issue was fixed in PowerISO 4.7, but Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue was fixed in PowerISO 4.7, but Symantec has not confirmed this. Please contact the vendor for more information.