vendor:
Mercury/32
by:
MC
7.5
CVSS
HIGH
Stack-based Buffer Overflow
119
CWE
Product Name: Mercury/32
Affected Version From: Unknown
Affected Version To: v4.01b
Patch Exists: NO
Related CWE: CVE-2005-4411
CPE: Mercury/32 PH Server Module
Platforms Tested: Windows XP Pro SP0/SP1 English, Windows 2000 Pro English ALL
2005
Mercury/32 <= v4.01b PH Server Module Buffer Overflow
This module exploits a stack-based buffer overflow in Mercury/32 <= v4.01b PH Server Module. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to a fixed size memory buffer.
Mitigation:
Update to a fixed version of Mercury/32 PH Server Module (v4.01c or later).