Global Mapper Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
BID:59360
Info
Global Mapper Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
| Bugtraq ID: | 59360 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0727 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 22 2013 12:00AM |
| Updated: | Mar 19 2015 09:07AM |
| Credit: | Parvez Anwar via Secunia |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Global Mapper Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
Global Mapper is prone to multiple vulnerabilities that lets attackers execute arbitrary code.
Successful exploits will allow the attackers to execute arbitrary code in the context of the user running the affected application.
Global Mapper 14.1.0 is vulnerable; other versions may also be affected.
Global Mapper is prone to multiple vulnerabilities that lets attackers execute arbitrary code.
Successful exploits will allow the attackers to execute arbitrary code in the context of the user running the affected application.
Global Mapper 14.1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Global Mapper Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
Attackers can exploit these issues using standard commands.
Attackers can exploit these issues using standard commands.
Solution / Fix
Global Mapper Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Global Mapper Multiple Insecure Library Loading Arbitrary Code Execution Vulnerabilities
References:
References:
- Global Mapper Homepage (Blue Marble Geographics)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- Microsoft Security Advisory (2269637) (Microsoft)