EViews Multiple Memory Corruption Vulnerabilities
BID:49698
Info
EViews Multiple Memory Corruption Vulnerabilities
| Bugtraq ID: | 49698 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2011 12:00AM |
| Updated: | Sep 19 2011 12:00AM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
IHS Inc EViews 7.0 1 |
| Not Vulnerable: | |
Discussion
EViews Multiple Memory Corruption Vulnerabilities
EViews is prone to multiple memory-corruption vulnerabilities.
An attacker can exploit these issues by enticing an unsuspecting user to open a specially crafted 'WF1' or 'PRG' file.
A successful attack will allow attacker-supplied code to run in the context of the application or cause a denial-of-service condition.
EViews versions 7.0.0.1 and prior are affected.
EViews is prone to multiple memory-corruption vulnerabilities.
An attacker can exploit these issues by enticing an unsuspecting user to open a specially crafted 'WF1' or 'PRG' file.
A successful attack will allow attacker-supplied code to run in the context of the application or cause a denial-of-service condition.
EViews versions 7.0.0.1 and prior are affected.
Exploit / POC
EViews Multiple Memory Corruption Vulnerabilities
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
EViews Multiple Memory Corruption Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
EViews Multiple Memory Corruption Vulnerabilities
References:
References:
- EViews Homepage (IHS Inc)
- EViews Advisory (Luigi Auriemma)