CORE IMPACT v8 - Exploits Update (Thu Mar 26 2009)
Orbit Downloader Connecting Log Message Buffer Overflow Exploit
Exploits/Client Side [Windows]
Thu Mar 26 2009
The application is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. Specifically, this issue occurs when the application creates a 'Connecting' log message. An attacker can exploit this issue by enticing a vulnerable user into connecting to a malicious HTTP server or opening a specially crafted URI that contains an excessively long hostname.
Exploits Vulnerabiltiy: CVE-2009-0187











