vendor:
SAWStudio 3.9i
by:
Encrypt3d.M!nd
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: SAWStudio 3.9i
Affected Version From: 3.9i
Affected Version To: 3.9i
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2008
SAWStudio 3.9i (prf file) Buffer overflow Poc
When a long character is imported into the SAWStudio 3.9i prf file, a buffer overflow occurs, resulting in the registers EAX:41414141 ECX:00000000 EDX:00561498 EBX:00000000 ESP:0012DA5C EBP:0012FAD0 ESI:00561498 EDI:00000000 EIP:7C91B1FA ntdll.7C91B1FA and an access violation when writing to [41414151].
Mitigation:
Ensure that the prf file is not imported with long characters.