WSMP3 Multiple Buffer Overflow Vulnerabilities
BID:6239
Info
WSMP3 Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 6239 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2002 12:00AM |
| Updated: | Nov 25 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "dong-h0un U" <[email protected]>. |
| Vulnerable: |
WSMP3 WSMP3 0.0.2 WSMP3 WSMP3 0.0.1 |
| Not Vulnerable: | |
Discussion
WSMP3 Multiple Buffer Overflow Vulnerabilities
Several buffer overflow conditions have been reported for WSMP3. The vulnerability is due to improper bounds checking when copying data to local buffers.
An attacker can exploit this vulnerability by sending an overly long request to the vulnerable server. This will trigger the buffer overflow condition, resulting in memory corruption. Ovewriting sensitive memory with malicious values may allow an attacker to execute arbitrary code on the target system.
Several buffer overflow conditions have been reported for WSMP3. The vulnerability is due to improper bounds checking when copying data to local buffers.
An attacker can exploit this vulnerability by sending an overly long request to the vulnerable server. This will trigger the buffer overflow condition, resulting in memory corruption. Ovewriting sensitive memory with malicious values may allow an attacker to execute arbitrary code on the target system.
Exploit / POC
WSMP3 Multiple Buffer Overflow Vulnerabilities
The following proof of concept has been provided by dong-houn yoU:
(echo "GET `perl -e 'print \"x\"x2000'`";cat)|nc 0 8000
The following proof of concept has been provided by dong-houn yoU:
(echo "GET `perl -e 'print \"x\"x2000'`";cat)|nc 0 8000
References
WSMP3 Multiple Buffer Overflow Vulnerabilities
References:
References:
- WSMP3 Home Page (WSMP3)
- Remote Heap malloc/free & multiple Overflow vulnerability in WSMP3. ("dong-h0un U"
)