vendor:
Blat
by:
hyp3rlinx
7.5
CVSS
HIGH
Stack Buffer Overflow
120
CWE
Product Name: Blat
Affected Version From: 2.7.2006
Affected Version To: 2.7.2006
Patch Exists: NO
Related CWE:
CPE: blat:blat:2.7.6
Platforms Tested: Windows
Blat Mailer Buffer Overflow
An older release of blat.exe v2.7.6 is prone to a stack based buffer overflow when sending malicious command line arguments. The vulnerability can be triggered by sending two arguments, the first one can be any value e.g. 'AAAA', and the second argument triggers the buffer overflow and allows execution of arbitrary code on the victim's OS.
Mitigation:
Upgrade to the latest version of Blat.