vendor:
Castripper
by:
mr_me
7,8
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: Castripper
Affected Version From: 2.50.70
Affected Version To: 2.50.70
Patch Exists: YES
Related CWE: N/A
CPE: a:mini-stream:castripper
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2009
Castripper 2.50.70 (.pls) stack buffer overflow w/ DEP bypass exploit
Castripper 2.50.70 is vulnerable to a stack buffer overflow vulnerability when a specially crafted .pls file is opened. This exploit bypasses DEP by using a combination of gadgets from the application's DLL and a hardcoded wpm() and XCHG EAX,EBX from ntdll.dll (non-ASLR).
Mitigation:
Update to the latest version of Castripper 2.50.70