Baidu Spark Browser Stack Overflow Denial of Service Vulnerability
BID:68288
Info
Baidu Spark Browser Stack Overflow Denial of Service Vulnerability
| Bugtraq ID: | 68288 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-5349 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2014 12:00AM |
| Updated: | Aug 21 2014 12:03AM |
| Credit: | Gjoko 'LiquidWorm' Krstic |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Baidu Spark Browser Stack Overflow Denial of Service Vulnerability
Baidu Spark Browser is prone to a remote denial-of-service vulnerability.
Successful exploits can allow attackers to crash the affected browser, resulting in denial-of-service conditions. Given the nature of this issue, attackers may also be able to corrupt process memory and execute arbitrary code, but this has not been confirmed.
Baidu Spark Browser 26.5.9999.3511 is vulnerable; other versions may also be affected.
Baidu Spark Browser is prone to a remote denial-of-service vulnerability.
Successful exploits can allow attackers to crash the affected browser, resulting in denial-of-service conditions. Given the nature of this issue, attackers may also be able to corrupt process memory and execute arbitrary code, but this has not been confirmed.
Baidu Spark Browser 26.5.9999.3511 is vulnerable; other versions may also be affected.
Exploit / POC
Baidu Spark Browser Stack Overflow Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Baidu Spark Browser Stack Overflow Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Baidu Spark Browser Stack Overflow Denial of Service Vulnerability
References:
References: