Vulnerabilities > CVE-2008-0550 - Numeric Errors vulnerability in Radio Toolbox Steamcast

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
radio-toolbox
CWE-189
critical
exploit available
metasploit

Summary

Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.

Vulnerable Configurations

Part Description Count
Application
Radio_Toolbox
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionStreamcast. CVE-2008-0550. Remote exploit for windows platform
idEDB-ID:16800
last seen2016-02-02
modified2010-06-11
published2010-06-11
reportermetasploit
sourcehttps://www.exploit-db.com/download/16800/
titleStreamcast <= 0.9.75 HTTP User-Agent Buffer Overflow

Metasploit

descriptionThis module exploits a stack buffer overflow in Streamcast <= 0.9.75. By sending an overly long User-Agent in an HTTP GET request, an attacker may be able to execute arbitrary code.
idMSF:EXPLOIT/WINDOWS/HTTP/STEAMCAST_USERAGENT
last seen2020-06-12
modified2017-11-08
published2009-02-25
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/http/steamcast_useragent.rb
titleStreamcast HTTP User-Agent Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83026/steamcast_useragent.rb.txt
idPACKETSTORM:83026
last seen2016-12-05
published2009-11-26
reporterLSO
sourcehttps://packetstormsecurity.com/files/83026/Streamcast-0.9.75-HTTP-User-Agent-Buffer-Overflow.html
titleStreamcast <= 0.9.75 HTTP User-Agent Buffer Overflow