vendor:
OTSTurntables
by:
milw0rm.com
N/A
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: OTSTurntables
Affected Version From: 1.00
Affected Version To: 1.00
Patch Exists: NO
Related CWE:
CPE: a:otsturntables:otsturntables:1.00
Platforms Tested:
2007
OTSTurntables 1.00 Buffer Overflow 0days
The exploit uses a buffer overflow vulnerability in OTSTurntables 1.00 to execute arbitrary code. It overflows a buffer with a length of 277 characters, then overwrites the EIP (Extended Instruction Pointer) with the address of the 'jmp esp' instruction in shell32.dll on Windows XP SP0. It also contains a shellcode of 224 bytes. If the SEH (Structured Exception Handling) method is used, additional information is provided. The exploit was created by the author with the value 0x58.
Mitigation:
Update to a patched version of OTSTurntables that addresses the buffer overflow vulnerability. Avoid using vulnerable versions of the software.