Exceed Font Name Handler Buffer Overflow Vulnerability
BID:8194
Info
Exceed Font Name Handler Buffer Overflow Vulnerability
| Bugtraq ID: | 8194 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2003 12:00AM |
| Updated: | Jul 15 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to [email protected]. |
| Vulnerable: |
Hummingbird Exceed 8.0 Hummingbird Exceed 7.1.1 Hummingbird Exceed 7.1 Hummingbird Exceed 6.1 Hummingbird Exceed 6.0.2 Hummingbird Exceed 6.0.1 Hummingbird Exceed 5.0 |
| Not Vulnerable: | |
Discussion
Exceed Font Name Handler Buffer Overflow Vulnerability
The Exceed server and client have been reported prone to a remotely triggered buffer overflow vulnerability. An attacker may trigger this vulnerability by sending excessive data as a font name to the server via a malicios XLoadQueryFont() request, or by passing a malicious font name from the server to the client in a manner sufficient to trigger the overflow. When the vulnerable software handles this request it will crash.
The Exceed server and client have been reported prone to a remotely triggered buffer overflow vulnerability. An attacker may trigger this vulnerability by sending excessive data as a font name to the server via a malicios XLoadQueryFont() request, or by passing a malicious font name from the server to the client in a manner sufficient to trigger the overflow. When the vulnerable software handles this request it will crash.
Exploit / POC
Exceed Font Name Handler Buffer Overflow Vulnerability
The following proof of concept code has been supplied:
The following proof of concept code has been supplied:
Solution / Fix
Exceed Font Name Handler Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Exceed Font Name Handler Buffer Overflow Vulnerability
References:
References:
- Exceed Homepage (Hummingbird LTD.)
- Exceed.c (Packetstorm)