vendor:
Blat
by:
Unknown
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Blat
Affected Version From: 3.2.14
Affected Version To: 3.2.14
Patch Exists: Yes
Related CWE: N/A
CPE: a:blat:blat
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
Unknown
Blat v3.2.14 Overflow Vulnerability
The Overflow vulnerability lies in the profile option parameter “–p”. When a string of 236 bytes is send to blat, the EBP and EIP register gets overwritten by the user input. Reproduction: blat.exe crashes with this command blat.exe –install smtp.my.tld 127.0.0.1 –p <”A”*234+”B”*2>
Mitigation:
Update to the latest version of Blat