header-logo
Suggest Exploit
vendor:
Platinum SDK
by:
n00b (Realname: Carl Cope)
7,5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Platinum SDK
Affected Version From: Platinum-SRC-0-6-0_632
Affected Version To: Platinum-SRC-0-6-0_632
Patch Exists: YES
Related CWE: N/A
CPE: platinum/platinum
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, Vista SP2, Linux Ubuntu
2010

Platinum SDK library post upnp sscanf buffer overflow

First of all while i was testing the upnp in the xbmc application i noticed after finding the vulnerable function in the source code it was because of the Platinum UPnP SDK which was used for upnp protocol. There are more applications vulnerable to this exploit than i had first thought im not writing an exploit for them all as it would be pointless i've passed the information to the developers of platinum sdk and when they have updated so will the rest of the vendors hope fully. Any thing which uses this sdk is exploitable if you do decide to write an exploit for any of the vulnerable applications please give credits to n00b for finding the bug.!! The vendor has released a fix for this vulnerability http://kent.dl.sourceforge.net/project/platinum/platinum/0.6.1/CHANGELOG.txt I would like to thank the vendor of the sdk for taking swift action and fixing this vulnerability swiftly 10/10 for communications and working to get this issue resolved.

Mitigation:

Upgrade to Platinum 0.6.1 or later
Source

Exploit-DB raw data: