ERDAS ER Viewer 'ERM_convert_to_correct_webpath()' Function Stack Buffer Overflow Vulnerability
BID:59379
Info
ERDAS ER Viewer 'ERM_convert_to_correct_webpath()' Function Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 59379 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-0726 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 23 2013 12:00AM |
| Updated: | May 15 2013 06:52AM |
| Credit: | Parvez Anwar via Secunia. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ERDAS ER Viewer 'ERM_convert_to_correct_webpath()' Function Stack Buffer Overflow Vulnerability
ERDAS ER Viewer is prone to a stack-based buffer-overflow vulnerability because the software fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts likely result in denial-of-service conditions.
ERDAS ER Viewer 11.0.4 is vulnerable; other versions may also be affected.
ERDAS ER Viewer is prone to a stack-based buffer-overflow vulnerability because the software fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts likely result in denial-of-service conditions.
ERDAS ER Viewer 11.0.4 is vulnerable; other versions may also be affected.
Exploit / POC
ERDAS ER Viewer 'ERM_convert_to_correct_webpath()' Function Stack Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following metasploit exploit module is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following metasploit exploit module is available:
Solution / Fix
ERDAS ER Viewer 'ERM_convert_to_correct_webpath()' Function Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ERDAS ER Viewer 'ERM_convert_to_correct_webpath()' Function Stack Buffer Overflow Vulnerability
References:
References: