Lynx browser 'convert_to_idna()' Function Remote Heap Based Buffer Overflow Vulnerability
BID:42316
Info
Lynx browser 'convert_to_idna()' Function Remote Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 42316 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2010 12:00AM |
| Updated: | Aug 09 2010 12:00AM |
| Credit: | Dan Rosenberg |
| Vulnerable: |
University of Kansas Lynx 0 |
| Not Vulnerable: | |
Discussion
Lynx browser 'convert_to_idna()' Function Remote Heap Based Buffer Overflow Vulnerability
Lynx browser is prone to a remote heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary attacker-supplied code within the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.
Lynx browser is prone to a remote heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary attacker-supplied code within the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.
Exploit / POC
Lynx browser 'convert_to_idna()' Function Remote Heap Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Lynx browser 'convert_to_idna()' Function Remote Heap Based Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Lynx browser 'convert_to_idna()' Function Remote Heap Based Buffer Overflow Vulnerability
References:
References:
- Heap overflow when parsing malformed URLs (Dan Rosenberg)
- Lynx Homepage (Lynx)