PosterSoftware Publish-it '.PUI' File Handling Buffer Overflow Vulnerability
BID:65366
Info
PosterSoftware Publish-it '.PUI' File Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 65366 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-0980 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2014 12:00AM |
| Updated: | Aug 01 2014 12:02AM |
| Credit: | Daniel Kazimirow from Core Exploit Writers Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
PosterSoftware Publish-it '.PUI' File Handling Buffer Overflow Vulnerability
Publish-it is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Publish-it 3.6d is vulnerable; other versions may also be affected.
Publish-it is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Publish-it 3.6d is vulnerable; other versions may also be affected.
Exploit / POC
PosterSoftware Publish-it '.PUI' File Handling Buffer Overflow Vulnerability
A proof-of-concept code is available; please see the references for more information.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A proof-of-concept code is available; please see the references for more information.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
PosterSoftware Publish-it '.PUI' File Handling Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PosterSoftware Publish-it '.PUI' File Handling Buffer Overflow Vulnerability
References:
References: