ZippHo '.zip' File Stack-Based Buffer Overflow Vulnerability
BID:38836
Info
ZippHo '.zip' File Stack-Based Buffer Overflow Vulnerability
| Bugtraq ID: | 38836 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2010 12:00AM |
| Updated: | Mar 18 2010 12:00AM |
| Credit: | mr_me |
| Vulnerable: |
Nensor Nensor CMS 2.01 |
| Not Vulnerable: | |
Discussion
ZippHo '.zip' File Stack-Based Buffer Overflow Vulnerability
ZippHo is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker could exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
ZippHo 3.0.6 is vulnerable; other versions may also be affected.
ZippHo is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker could exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
ZippHo 3.0.6 is vulnerable; other versions may also be affected.
Exploit / POC
ZippHo '.zip' File Stack-Based Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available: