UnRTF RTF File Handling Out of Bounds Memory Corruption Vulnerability
BID:71430
Info
UnRTF RTF File Handling Out of Bounds Memory Corruption Vulnerability
| Bugtraq ID: | 71430 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-9274 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2014 12:00AM |
| Updated: | Jul 15 2015 01:00AM |
| Credit: | Michal Zalewski |
| Vulnerable: |
Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
UnRTF RTF File Handling Out of Bounds Memory Corruption Vulnerability
UnRTF is prone to a memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.
UnRTF is prone to a memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.
Exploit / POC
UnRTF RTF File Handling Out of Bounds Memory Corruption Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
UnRTF RTF File Handling Out of Bounds Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
UnRTF RTF File Handling Out of Bounds Memory Corruption Vulnerability
References:
References:
- UnRTF Homepage (GNU)