vendor:
ERS Viewer
by:
Parvez Anwar, juan vazquez
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ERS Viewer
Affected Version From: 11.04
Affected Version To: 11.04
Patch Exists: NO
Related CWE: CVE-2013-0726
CPE: ERS Viewer 2011
Platforms Tested: Windows
2013
ERS Viewer 2011 ERS File Handling Buffer Overflow
This module exploits a buffer overflow vulnerability found in ERS Viewer 2011 (version 11.04). The vulnerability exists in the module ermapper_u.dll where the function ERM_convert_to_correct_webpath handles user provided data in a insecure way. It results in arbitrary code execution under the context of the user viewing a specially crafted .ers file. This module has been tested successfully with ERS Viewer 2011 (version 11.04) on Windows XP SP3 and Windows 7 SP1.
Mitigation:
Unknown