vendor:
BigView
by:
Alfredo Ortega - Core Security Exploit Writers Team (EWT)
7.5
CVSS
HIGH
Stack-Based Buffer Overflow
119
CWE
Product Name: BigView
Affected Version From: 1.8
Affected Version To: Unknown (other versions may also be affected)
Patch Exists: NO
Related CWE:
CPE: a:nasa:bigview:1.8
Platforms Tested: Ubuntu 6.06 Desktop i386
Unknown
NASA Ames Research Center BigView Remote Stack-Based Buffer Overflow Vulnerability
The NASA Ames Research Center BigView application is prone to a remote stack-based buffer-overflow vulnerability. This vulnerability occurs due to a failure in properly bounds-checking user-supplied data before copying it to an insufficiently sized memory buffer. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application, potentially compromising the application and underlying computer. Failed exploit attempts may result in a denial of service.
Mitigation:
It is recommended to apply the latest updates and patches provided by the vendor to mitigate this vulnerability. Additionally, it is advised to implement proper input validation and bounds-checking mechanisms to prevent buffer-overflow vulnerabilities.