vendor:
Grabit
by:
Gaurav Baruah
8,8
CVSS
HIGH
SEH Overwrite Exploit
119
CWE
Product Name: Grabit
Affected Version From: 1.7.2 Beta 3
Affected Version To: 1.7.2 Beta 3
Patch Exists: YES
Related CWE: N/A
CPE: a:grabit:grabit
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 and XP SP2 (en)
2009
Grabit<=1.7.2 Beta 3 (.nzb) SEH Overwrite Exploit
Grabit is prone to a stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer. An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
Mitigation:
Upgrade to the latest version of Grabit.