vendor:
Magic ISO
by:
n00b
7.5
CVSS
HIGH
Stacked Based Buffer Overflow
Buffer Overflow
CWE
Product Name: Magic ISO
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2
Unknown
Magic ISO Stacked Based Buffer Overflow
Magic iso has a stacked based buffer overflow vulnerability when an overly-long file name is passed inside the .cue file. This allows an attacker to control registers and execute commands. This exploit is currently released as a denial-of-service proof of concept until further help is received. Debug information shows that registers eax, ecx, and edx can be controlled.
Mitigation:
Unknown