vendor:
OllyDBG, ImpREC
by:
Defsanguje
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: OllyDBG, ImpREC
Affected Version From: OllyDBG v1.10, ImpREC v1.7f
Affected Version To: OllyDBG v1.10, ImpREC v1.7f
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
OllyDBG v1.10 and ImpREC v1.7f export name buffer overflow vulnerability
This exploit targets OllyDBG v1.10 and ImpREC v1.7f. It is a buffer overflow vulnerability that can be triggered by loading a DLL into a process and attempting to attach OllyDBG or ImpREC to it. The included shellcode demonstrates a messagebox and is configured for OllyDBG. The bug was discovered and the PoC was coded by Defsanguje on July 7, 2008.
Mitigation:
Apply patches or updates provided by the vendor. Avoid loading untrusted DLLs into processes.