Vector: | Remote |
Severity: | High |
Patch: | Unpatched |
Impact: | Remote Code Execution (RCE) |
Software: | WideChapter 3.x |
A remote code execution vulnerability has been discovered in WideChapter URL.
Buffer overflow vulnerability exists when handling URLs. An attacker can a stack based buffer overflow overwriting the return address by tricking a user into viewing a malicious HTML document, which tries to open an overly long, specially crafted URL (517 characters or more).
Links: http://bsecurity.port5.com/advisories/widechapter.txt