ERDAS ER Viewer 'rf_report_error()' Function Stack Buffer Overflow Vulnerability
BID:60178
Info
ERDAS ER Viewer 'rf_report_error()' Function Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 60178 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-3482 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2013 12:00AM |
| Updated: | Jul 23 2013 02:23AM |
| Credit: | James Fitts via Secunia. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ERDAS ER Viewer 'rf_report_error()' Function Stack Buffer Overflow Vulnerability
ERDAS ER Viewer is prone to a stack-based buffer-overflow vulnerability because the software fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts likely result in denial-of-service conditions.
ERDAS ER Viewer 13.0.1.1298 is vulnerable; other versions may also be affected.
ERDAS ER Viewer is prone to a stack-based buffer-overflow vulnerability because the software fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts likely result in denial-of-service conditions.
ERDAS ER Viewer 13.0.1.1298 is vulnerable; other versions may also be affected.
Exploit / POC
ERDAS ER Viewer 'rf_report_error()' Function Stack Buffer Overflow Vulnerability
An attacker can exploit this issue using readily available tools.
The following Metasploit module is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
An attacker can exploit this issue using readily available tools.
The following Metasploit module is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
Solution / Fix
ERDAS ER Viewer 'rf_report_error()' Function Stack Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ERDAS ER Viewer 'rf_report_error()' Function Stack Buffer Overflow Vulnerability
References:
References: