Jump to content
YOUR-AD-HERE
HOSTING
TOOLS
992Proxy

Locked .NET Framework EncoderParameter Integer Overflow


1337day-Exploits

Recommended Posts

PacketStorm-Security Acaba de publicar lo siguiente:

 

This is the hidden content, please
;)

 

An integer overflow vulnerability has been discovered in the EncoderParameter class of the .NET Framework. Exploiting this vulnerability results in an overflown integer that is used to allocate a buffer on the heap. After the incorrect allocation, user-supplied buffers are copied into the new buffer, resulting in a corruption of the heap. By exploiting this vulnerability, it is possible for an application running with Partial Trust permissions to break from the CLR sandbox and run arbitrary code with Full Trust permissions.

 

 

13/02/2013 23:35

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.