vendor:
eSignal and eSignal Pro
by:
Luigi Auriemma, TecR0c, mr_me
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: eSignal and eSignal Pro
Affected Version From: eSignal and eSignal Pro <= 10.6.2425.1208
Affected Version To: eSignal and eSignal Pro <= 10.6.2425.1208
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, Windows Vista, Windows 7
2011
eSignal and eSignal Pro <= 10.6.2425.1208 file parsing buffer overflow in QUO
The software is unable to handle the "<StyleTemplate>" files (even those original included in the program) like those with the registered extensions QUO, SUM and POR. Successful exploitation of this vulnerability may take up to several seconds due to the use of egghunter. Also, DEP bypass is unlikely due to the limited space for payload.
Mitigation:
Ensure that all software is up to date and patched with the latest security updates.