vendor:
Altova DatabaseSpy 2011
by:
Gjoko 'Liquiid' Krstic
7,5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Altova DatabaseSpy 2011
Affected Version From: Enterprise Edition 2011
Affected Version To: Enterprise Edition 2011
Patch Exists: YES
Related CWE: N/A
CPE: a:altova:databasespy_2011_enterprise_edition
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (English)
2011
Altova DatabaseSpy 2011 Project File Handling Buffer Overflow Vulnerability
The Altova DatabaseSpy 2011 Enterprise Edition suffers from a buffer overflow/memory corruption vulnerability when handling project files (.qprj). The issue is triggered because there is no boundry checking of some XML tag property values, ex: <Folder FolderName="SQL" Type="AAAAAAA..../>" (~1000 bytes). This can aid the attacker to execute arbitrary machine code in the context of an affected node (locally and remotely) via file crafting or computer-based social engineering.
Mitigation:
Update to the latest version of Altova DatabaseSpy 2011 Enterprise Edition