vendor:
FlexHEX
by:
Rafael Pedrero
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FlexHEX
Affected Version From: 2.46
Affected Version To: 2.46
Patch Exists: YES
Related CWE: N/A
CPE: a:flexhex:flexhex:2.46
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP SP3
2018
FlexHEX v2.46 – Denial of Service (PoC) and SEH overwritten Crash PoC
FlexHEX v2.46 is vulnerable to a Denial of Service (DoS) Local Buffer Overflow. By copying the content of FlexHEX_SEH_Crash.txt to the 'Stream Name' field, a crash can be triggered. The SEH record (nseh field) at 0x0012dde8 is overwritten with unicode pattern : 0x006a0041 (offset 276), followed by 20 bytes of cyclic data after the handler.
Mitigation:
Upgrade to the latest version of FlexHEX.