vendor:
TVMOBiLi media server
by:
High-Tech Bridge Security Research Lab
5,5
CVSS
MEDIUM
Improper Handling of Length Parameter Inconsistency
130
CWE
Product Name: TVMOBiLi media server
Affected Version From: 2.1.0.3557
Affected Version To: 2.1.0.3557
Patch Exists: YES
Related CWE: CVE-2012-5451
CPE: a:tvmobili:tvmobili_media_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 32 bits
2012
Improper Handling of Length Parameter Inconsistency in TVMOBiLi
The vulnerability exists due to improper handling of URI length within the "HttpUtils.dll" dynamic-link library. A remote attacker can send a specially crafted HTTP GET request of 161, 257 or 255 characters long to 30888/TCP port (default TVMOBiLi's server port) and cause a stack-based buffer overrun that will crash tvMobiliService service.
Mitigation:
Fixed by Vendor