vendor:
Immunity Debugger
by:
Arsyntex
7.5
CVSS
HIGH
Crash
476
CWE
Product Name: Immunity Debugger
Affected Version From: v1.85
Affected Version To: v1.85
Patch Exists: NO
Related CWE:
CPE: cpe:2.3:a:immunity:immunity_debugger:1.85:*:*:*:*:*:*:*
Platforms Tested: Windows 8.1 Pro
2015
Immunity Debugger – Crash
The vulnerability exists in Immunity Debugger v1.85. It is caused by incorrect path/file extension parsing. By creating a folder with the name .exe.exe and placing any program inside, or by trying to debug an executable with the name test.exe.exe or lib.exe.dll, it is possible to trigger a crash. This is due to the 'OpenEXEfile' function not checking if the return value of strchr() is zero.
Mitigation:
The vendor should update Immunity Debugger to properly handle path/file extension parsing and validate return values from functions like strchr(). Users should also ensure they are using the latest version of Immunity Debugger and exercise caution when debugging executable files with unusual names.