PT-2009-3652 · Icarus · Icarus
His0K4
·
Published
2009-03-24
·
Updated
2017-10-04
·
CVE-2009-1071
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Icarus version 2.0
Description
The issue is a stack-based buffer overflow that allows remote attackers to cause a denial of service, resulting in an application crash, or execute arbitrary code. This is achieved by using a crafted Portable Game Notation (.pgn) file.
Recommendations
For Icarus version 2.0, avoid using the application to open .pgn files from untrusted sources until a patch is available. As a temporary workaround, consider restricting the use of .pgn file handling functionality to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Icarus