vendor:
N/A
by:
redsand@blacksecurity.org
7.5
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
sploit creater by redsand@blacksecurity.org
A heap overflow vulnerability exists in wmf.dll at 0x0035920a, which can be exploited to cause a denial of service. The exploit code is stolen from CANVAS code and is used to overwrite the EIP register with a call edi +20 for win2k pro eng in oleaut. The exploit code is written in Intel order and is appended with a tag '0wn3dbyr3ds4nd' at the end.
Mitigation:
N/A