vendor:
Liquid XML Studio 2010
by:
Steven Seeley (mr_me)
9,3
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: Liquid XML Studio 2010
Affected Version From: v8.061970
Affected Version To: v8.061970
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 (IE 6 & 7)
2010
Liquid XML Studio 2010 <= v8.061970 - (LtXmlComHelp8.dll) OpenFile() Remote 0day Heap Overflow Exploit
A heap overflow vulnerability exists in Liquid XML Studio 2010 <= v8.061970, which is caused by a boundary error when handling a specially crafted OpenFile() request. This can be exploited to cause a stack-based buffer overflow by e.g. enticing a user to open a specially crafted file. Successful exploitation may allow execution of arbitrary code.
Mitigation:
Upgrade to the latest version of Liquid XML Studio 2010.