vendor:
KingView
by:
Lucas Apa, Carlos Mario Penagos Hollman, juan vazquez
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: KingView
Affected Version From: KingView <= 6.55
Affected Version To: KingView <= 6.55
Patch Exists: NO
Related CWE: CVE-2012-4711
CPE: a:kingview:kingview:6.55
Platforms Tested: Windows XP SP3
2012
KingView Log File Parsing Buffer Overflow
This module exploits a vulnerability found in KingView <= 6.55. It exists in the KingMess.exe application when handling log files, due to the insecure usage of sprintf. This module uses a malformed .kvl file which must be opened by the victim via the KingMess.exe application, through the 'Browse Log Files' option. The module has been tested successfully on KingView 6.52 and KingView 6.53 Free Trial over Windows XP SP3.
Mitigation:
Unknown