XLReader 0.9 - Remote Client-Side Buffer Overflow
Author: Kris Kubicki
type: remote
platform: multiple
port:
date_added: 2004-12-16
date_updated: 2013-04-30
verified: 1
codes: CVE-2004-1301;OSVDB-11970
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/11970/info
A remote, client-side buffer overflow vulnerability affects xlreader. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/24979.zip