Vulnerabilities > CVE-2005-0308 - Buffer Overflow vulnerability in Ursoftware W32Dasm 8.94

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ursoftware
exploit available
metasploit

Summary

Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export function name.

Vulnerable Configurations

Part Description Count
Application
Ursoftware
1

Exploit-Db

descriptionURSoft W32Dasm Disassembler Function Buffer Overflow. CVE-2005-0308. Local exploit for windows platform
idEDB-ID:16645
last seen2016-02-02
modified2010-09-25
published2010-09-25
reportermetasploit
sourcehttps://www.exploit-db.com/download/16645/
titleURSoft W32Dasm Disassembler Function Buffer Overflow

Metasploit

descriptionThis module exploits a buffer overflow in W32Dasm <= v8.93. By creating a malicious file and convincing a user to disassemble the file with a vulnerable version of W32Dasm, the Imports/Exports function is copied to the stack and arbitrary code may be executed locally as the user.
idMSF:EXPLOIT/WINDOWS/FILEFORMAT/URSOFT_W32DASM
last seen2020-01-16
modified2020-01-15
published2009-01-07
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/fileformat/ursoft_w32dasm.rb
titleURSoft W32Dasm Disassembler Function Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/82970/ursoft_w32dasm.rb.txt
idPACKETSTORM:82970
last seen2016-12-05
published2009-11-26
reporterpatrick
sourcehttps://packetstormsecurity.com/files/82970/URSoft-W32Dasm-Disassembler-Function-Buffer-Overflow.html
titleURSoft W32Dasm Disassembler Function Buffer Overflow