Microsoft IE Yamaha MidiPlug Buffer Overflow Vulnerability
BID:760
Info
Microsoft IE Yamaha MidiPlug Buffer Overflow Vulnerability
| Bugtraq ID: | 760 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 02 1999 12:00AM |
| Updated: | Nov 02 1999 12:00AM |
| Credit: | This vulnerability was posted to Bugtraq by UNYUN <[email protected]>. |
| Vulnerable: |
Yamaha MidiPlug 1.1 b-j |
| Not Vulnerable: | |
Discussion
Microsoft IE Yamaha MidiPlug Buffer Overflow Vulnerability
There is a buffer overflow in the MidiPlug that may allow arbitrary code to be executed on the local host. This overflow occurs if a long "Text" variable is specified within an EMBED tag in a web page. Instructions in the text variable may be executed when a user visits the malicious web page.
There is a buffer overflow in the MidiPlug that may allow arbitrary code to be executed on the local host. This overflow occurs if a long "Text" variable is specified within an EMBED tag in a web page. Instructions in the text variable may be executed when a user visits the malicious web page.
Exploit / POC
Microsoft IE Yamaha MidiPlug Buffer Overflow Vulnerability
Exploit available:
Exploit available:
Solution / Fix
Microsoft IE Yamaha MidiPlug Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Microsoft IE Yamaha MidiPlug Buffer Overflow Vulnerability
References:
References:
- Penguin Toolbox #51 (Shadow Penguin Security)