PT-2015-3531 · Tvmobili · Tvmobili
Published
2015-04-24
·
Updated
2015-04-27
·
CVE-2012-5451
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
TVMOBiLi versions prior to 2.1.0.3974
Description
The issue is related to multiple stack-based buffer overflows in HttpUtils.dll, which can be exploited by remote attackers. This can be achieved by sending a long string in a GET or HEAD request to TCP port 30888, resulting in a denial of service, specifically causing the tvMobiliService service to crash.
Recommendations
For versions prior to 2.1.0.3974, update to version 2.1.0.3974 or later to resolve the issue. As a temporary workaround, consider restricting access to TCP port 30888 to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tvmobili