WinAce UUE File Decompression Buffer Overflow

Posted on Tuesday, December 25, 2007 @ 17:37:46 CST in Security
by Raven

SECUNIA ADVISORY ID: SA28215

VERIFY ADVISORY: http://secunia.com/advisories/28215/

CRITICAL: Highly critical

IMPACT: System access

SOFTWARE: WinAce 2.x - http://secunia.com/product/4231/

DESCRIPTION: A vulnerability has been reported in WinAce, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error when decompressing UUE files and can be exploited to cause a heap-based buffer overflow via a specially crafted UUE file containing an overly long filename. Successful exploitation may allow execution of arbitrary code. The vulnerability is reported in version 2.65. Other versions may also be affected.

SOLUTION: Update to version 2.69. - http://www.winace.com/down.html

PROVIDED AND/OR DISCOVERED BY: Fourteenforty Research Institute

ORIGINAL ADVISORY: http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20071225

OTHER REFERENCES: JVN: http://jvn.jp/jp/JVN%2344736880/index.html
 
 
click Related        click Share
 
News ©

Site Info

Last SeenLast Seen
  • vashd1
  • neralex
Server TrafficServer Traffic
  • Total: 513,582,747
  • Today: 39,203
Server InfoServer Info
  • Apr 26, 2025
  • 10:28 am CDT