Format string vulnerability in DataRescue Interactive Disassembler and Debugger (IDA) Pro 4.7.0.830 allows remote attackers or local users to cause a denial of service (CPU consumption or application crash) and possibly execute arbitrary code via format string specifiers in a dynamic link library (DLL) name.
Link | Tags |
---|---|
http://pb.specialised.info/all/adv/ida-debugger-adv.txt | exploit |
http://www.datarescue.com/cgi-local/ultimatebb.cgi?ubb=get_topic%3Bf=2%3Bt=000155%3Bp=0 | |
http://secunia.com/advisories/14610 | patch vendor advisory third party advisory |
http://marc.info/?l=bugtraq&m=111100269512216&w=2 | mailing list |