Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 01-30-2005, 13:35
NimDa2k's Avatar
NimDa2k NimDa2k is offline
Friend
 
Join Date: Jan 2005
Posts: 124
Rept. Given: 3
Rept. Rcvd 2 Times in 1 Post
Thanks Given: 1
Thanks Rcvd at 8 Times in 5 Posts
NimDa2k Reputation: 3
Code:
 TITLE:
PEiD Import Library Name Handling Buffer Overflow

SECUNIA ADVISORY ID:
SA13984

RELEASE DATE:
2005-01-28

VERIFY ADVISORY:
http://secunia.com/advisories/13984/

CRITICAL:
Moderately critical

WHERE:
From remote

IMPACT:
System access

SOFTWARE:
PEiD 0.x

DESCRIPTION:
A vulnerability has been reported in PEiD, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error within the parsing of the PE (Portable Executable) import directory. This can be exploited to cause a buffer overflow via a specially crafted PE file containing overly long import library names.

Successful exploitation may allow execution of arbitrary code when a malicious PE file is opened.


SOLUTION:
Use another product.

Do not process untrusted files unless in a test environment.


REPORTED BY CREDITS:
Lord Yup


ORIGINAL ADVISORY:
iDEFENSE:
http://idefense.com/application/...?id=189&type=vulnerabilities
I Think This Bug Work's Only When I Connected To The Internet And i Use PEiD
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
A CRITICAL Firefox Vuln - Violation and local file stealing via PDF reader TechLord General Discussion 3 08-15-2015 15:39
Need help in exploiting a kernel vuln SinaDiR General Discussion 0 01-10-2011 23:21


All times are GMT +8. The time now is 22:08.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )