vendor:
IP2Location.dll
by:
sinn3r
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: IP2Location.dll
Affected Version From: v1.0.0.1
Affected Version To: v1.0.0.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
IP2Location.dll v1.0.0.1 Initialize() Buffer Overflow by sinn3r
IP2Location.dll v1.0.0.1 Initialize() Buffer Overflow is a vulnerability found and coded by sinn3r. It was discovered in the IP2Location.dll v1.0.0.1 library, which is vulnerable to a buffer overflow attack. The vulnerability can be exploited by constructing a malicious buffer and passing it to the Initialize() function. This will cause the program to crash and potentially allow an attacker to execute arbitrary code.
Mitigation:
The vendor has released a patched version of the library, v3.0.1.0, which should be used instead of the vulnerable version.