WSMP3 Request Data Heap Overflow Vulnerability
BID:7643
Info
WSMP3 Request Data Heap Overflow Vulnerability
| Bugtraq ID: | 7643 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2003 12:00AM |
| Updated: | May 21 2003 12:00AM |
| Credit: | Discovery of this issue is credited to "dong-h0un U" <[email protected]>. |
| Vulnerable: |
WSMP3 WSMP3 0.0.10 WSMP3 WSMP3 0.0.9 WSMP3 WSMP3 0.0.8 WSMP3 WSMP3 0.0.7 |
| Not Vulnerable: | |
Discussion
WSMP3 Request Data Heap Overflow Vulnerability
WSMP3 is prone to a remotely exploitable heap overflow. Insufficient bounds checking of request data could result in corruption of heap memory. It is possible to exploit this issue to execute malicious instructions with the privileges of the WSMP3 server.
WSMP3 is prone to a remotely exploitable heap overflow. Insufficient bounds checking of request data could result in corruption of heap memory. It is possible to exploit this issue to execute malicious instructions with the privileges of the WSMP3 server.
Exploit / POC
WSMP3 Request Data Heap Overflow Vulnerability
The following exploit was provided:
The following exploit was provided:
Solution / Fix
WSMP3 Request Data Heap Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WSMP3 Request Data Heap Overflow Vulnerability
References:
References:
- WSMP3 Home Page (WSMP3)
- [INetCop Security Advisory] Remote Heap Corruption Overflow vulnerability ("dong-h0un U"
)