GetRight Buffer Overflow Vulnerability
- 0
- Add a Comment
Secunia Advisory SA13391
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: GetRight 5.x
ATmaCA has reported a vulnerability in GetRight, which potentially can be exploited by malicious people to compromise a user’s system.
The vulnerability is caused due to a boundary error in a 3rd-party compression library (DUNZIP32.dll) when processing skin files. This can be exploited by e.g. a malicious Web site to cause a buffer overflow via a specially crafted skin file.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is related to:
SA12805
The vulnerability has been reported in version 5.2a. Prior versions may also be affected.
Solution:
Update to version 5.2b.
