vendor:
WebAccess Client
by:
Luigi Auriemma
7.5
CVSS
HIGH
Format String and Arbitrary Memory Corruption
134, 787
CWE
Product Name: WebAccess Client
Affected Version From: bwocxrun.ocx <= 1.0.0.10 (aka version 7.0)
Affected Version To: bwocxrun.ocx <= 1.0.0.10 (aka version 7.0)
Patch Exists: NO
Related CWE: N/A
CPE: a:broadwin:webaccess_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2011
BroadWin WebAccess Client
The OcxSpool function is affected by a format string vulnerability caused by the usage of the Msg string provided by the attacker directly with vsprintf() without the required format argument. WriteTextData and CloseFile allow to corrupt arbitrary zones of the memory through a fully controllable stream identifier in fclose() and fwrite().
Mitigation:
No fix.