Immunity Debugger HTTP Request Buffer Overflow Vulnerability
BID:46979
Info
Immunity Debugger HTTP Request Buffer Overflow Vulnerability
| Bugtraq ID: | 46979 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2011 12:00AM |
| Updated: | Mar 22 2011 12:00AM |
| Credit: | Paul Harrington |
| Vulnerable: |
Immunity Immunity Debugger 1.73 |
| Not Vulnerable: |
Immunity Immunity Debugger 1.82 |
Discussion
Immunity Debugger HTTP Request Buffer Overflow Vulnerability
Immunity Debugger is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Immunity Debugger 1.73 is vulnerable; other versions may also be affected.
Immunity Debugger is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Immunity Debugger 1.73 is vulnerable; other versions may also be affected.
Exploit / POC
Immunity Debugger HTTP Request Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Immunity Debugger HTTP Request Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
Immunity Debugger HTTP Request Buffer Overflow Vulnerability
References:
References:
- Immunity Debugger Homepage (Immunity)
- NGS00016 Technical Advisory: Immunity Debugger Buffer Overflow (Research@NGSSecure)