vendor:
Mobipocket Reader
by:
shinnai
8,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Mobipocket Reader
Affected Version From: 6.2 Build 608
Affected Version To: 6.2 Build 608
Patch Exists: YES
Related CWE: CVE-2011-4010
CPE: o:mobipocket.com:mobipocket_reader:6.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 7 Professional
2011
Mobipocket Reader version 6.2 Build 608 Buffer Overflow
Mobipocket Reader version 6.2 Build 608 is vulnerable to a buffer overflow vulnerability. The vulnerability is caused due to a boundary error within the processing of the .prc file. By exploiting this vulnerability, an attacker can execute arbitrary code in the context of the application.
Mitigation:
Upgrade to the latest version of Mobipocket Reader.