Microchip TCP/IP Stack Heap Based Buffer Overflow Vulnerability
BID:59603
Info
Microchip TCP/IP Stack Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 59603 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2013 12:00AM |
| Updated: | May 01 2013 12:00AM |
| Credit: | Unknown |
| Vulnerable: |
Microchip Technology Microchip TCP/IP stack 6.02 Microchip Technology Microchip TCP/IP stack 6.00 |
| Not Vulnerable: | |
Discussion
Microchip TCP/IP Stack Heap Based Buffer Overflow Vulnerability
Microchip TCP/IP Stack is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Microchip TCP/IP Stack is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Microchip TCP/IP Stack Heap Based Buffer Overflow Vulnerability
Currently, we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microchip TCP/IP Stack Heap Based Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].