Sterling Trader Remote Integer Overflow Vulnerability
BID:49758
Info
Sterling Trader Remote Integer Overflow Vulnerability
| Bugtraq ID: | 49758 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2011 12:00AM |
| Updated: | Sep 26 2011 12:00AM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Sterling Trader Sterling Trader 7.0.2 |
| Not Vulnerable: | |
Discussion
Sterling Trader Remote Integer Overflow Vulnerability
Sterling Trader is prone to a remote integer-overflow vulnerability because it fails to properly validate user-supplied input.
Attackers can exploit this issue to run arbitrary code within the context of the application. Failed exploit attempts may crash the affected application, denying service to legitimate users.
Sterling Trader versions 7.0.2 and prior are vulnerable.
Sterling Trader is prone to a remote integer-overflow vulnerability because it fails to properly validate user-supplied input.
Attackers can exploit this issue to run arbitrary code within the context of the application. Failed exploit attempts may crash the affected application, denying service to legitimate users.
Sterling Trader versions 7.0.2 and prior are vulnerable.
Exploit / POC
Sterling Trader Remote Integer Overflow Vulnerability
The researcher has created a proof-of-concept. Please see the references for more information.
The researcher has created a proof-of-concept. Please see the references for more information.
Solution / Fix
Sterling Trader Remote Integer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Sterling Trader Remote Integer Overflow Vulnerability
References:
References:
- Product Homepage (Sterling Trader)
- Sterling Trader integer overflow (Luigi Auriemma)