IDAPython Script Loading Arbitrary Code Execution Vulnerability
BID:51164
Info
IDAPython Script Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 51164 |
| Class: | Design Error |
| CVE: |
CVE-2011-4783 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2011 12:00AM |
| Updated: | Dec 22 2011 12:00AM |
| Credit: | Haifei Li, Microsoft Malware Protection Center (MMPC) |
| Vulnerable: |
IDAPython IDAPython 1.5.2 IDAPython IDAPython 1.5 Hex-Ray IDA Pro 6.0 Hex-Ray IDA Pro 5.7 |
| Not Vulnerable: |
IDAPython IDAPython 1.5.2.3 Hex-Ray IDA Pro 6.2 |
Discussion
IDAPython Script Loading Arbitrary Code Execution Vulnerability
IDAPython is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted script file.
IDAPython versions 1.5.0 through 1.5.2 are vulnerable; other versions may also be affected.
IDAPython is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted script file.
IDAPython versions 1.5.0 through 1.5.2 are vulnerable; other versions may also be affected.
Exploit / POC
IDAPython Script Loading Arbitrary Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IDAPython Script Loading Arbitrary Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
IDAPython Script Loading Arbitrary Code Execution Vulnerability
References:
References: