UltraEdit Spell Checker Stack Based Buffer Overflow Vulnerability
BID:41745
Info
UltraEdit Spell Checker Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 41745 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2010 12:00AM |
| Updated: | Jul 16 2010 12:00AM |
| Credit: | SkyLined |
| Vulnerable: |
IDM Computer Solutions UltraEdit 16.00 IDM Computer Solutions UltraEdit 15.20 |
| Not Vulnerable: |
IDM Computer Solutions UltraEdit 16.10 |
Discussion
UltraEdit Spell Checker Stack Based Buffer Overflow Vulnerability
UltraEdit is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
UltraEdit 15.20 and 16.00 are vulnerable; other versions may also be affected.
UltraEdit is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
UltraEdit 15.20 and 16.00 are vulnerable; other versions may also be affected.
Exploit / POC
UltraEdit Spell Checker Stack Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
UltraEdit Spell Checker Stack Based Buffer Overflow Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
UltraEdit Spell Checker Stack Based Buffer Overflow Vulnerability
References:
References:
- Issue 2: Stack buffer overrun vulnerability in UEdit32 throught GNU Aspell (Berend Janwever)
- UltraEdit Product Page (IDM Computer Solutions, Inc.)