UPEK Protector Suite QL '.vtp' File Buffer Overflow Vulnerability
BID:49592
Info
UPEK Protector Suite QL '.vtp' File Buffer Overflow Vulnerability
| Bugtraq ID: | 49592 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2011 12:00AM |
| Updated: | Sep 26 2011 07:20PM |
| Credit: | Vulnerability Lab |
| Vulnerable: |
AuthenTec UPEK Protector Suite QL 5.0 AuthenTec UPEK Protector Suite QL 2011 |
| Not Vulnerable: | |
Discussion
UPEK Protector Suite QL '.vtp' File Buffer Overflow Vulnerability
UPEK Protector Suite QL is prone to a buffer overflow vulnerability because it fails to do a proper bounds check of user-supplied input.
Attackers can exploit this issue to execute arbitrary code. Failed attempts will cause denial-of-service conditions.
UPEK Protector Suite QL 2011 and 5.0 are vulnerable; other versions may also be affected.
UPEK Protector Suite QL is prone to a buffer overflow vulnerability because it fails to do a proper bounds check of user-supplied input.
Attackers can exploit this issue to execute arbitrary code. Failed attempts will cause denial-of-service conditions.
UPEK Protector Suite QL 2011 and 5.0 are vulnerable; other versions may also be affected.
Exploit / POC
UPEK Protector Suite QL '.vtp' File Buffer Overflow Vulnerability
The reporter has developed a proof of concept. Please see the references for details.
The reporter has developed a proof of concept. Please see the references for details.
Solution / Fix
UPEK Protector Suite QL '.vtp' File Buffer Overflow Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
UPEK Protector Suite QL '.vtp' File Buffer Overflow Vulnerability
References:
References:
- Upek Protector Suite QL 2011 - Buffer Overflow Vulnerability (Vulnerability Research Laboratory)
- Upek Protector Suite QL 2011 - VTP Buffer Overflow Vulnerability (vulnerability-lab.com)
- UPEK Protector Suite QL Homepage (AuthenTec)