Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v8 - Exploits Update (Thu Mar 26 2009)

Orbit Downloader Connecting Log Message Buffer Overflow Exploit

Exploits/Client Side  [Windows]




• Thu Mar 26 2009
The application is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. Specifically, this issue occurs when the application creates a 'Connecting' log message. An attacker can exploit this issue by enticing a vulnerable user into connecting to a malicious HTTP server or opening a specially crafted URI that contains an excessively long hostname.

Exploits Vulnerabiltiy: CVE-2009-0187



< Back to Product Updates