vendor:
BOINC Manager
by:
xis_one@STM Solutions
3.3
CVSS
LOW
Field stack based buffer overflow
Buffer Overflow
CWE
Product Name: BOINC Manager
Affected Version From: 7.0.64
Affected Version To: 7.1.2002
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows
2013
BOINC Manager 7.0.64 Field stack based buffer overflow
BOINC Manager 7.0.64 is vulnerable to a field stack based buffer overflow. An attacker can exploit this vulnerability by convincing the victim to use a very long URL as the Account Manager URL. This can be done by generating the URL using the provided exploit. The severity of this vulnerability is low.
Mitigation:
The developers team at berkley.edu was informed about the issue and released BOINC 7.1.3 version which includes the fix for this vulnerability.