Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1254
    posted: 09/05/08
  • NSM Daily Update #1254
    posted: 09/05/08
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1254
    posted: 09/05/08
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1252
    posted: 09/05/08
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 09/05/08

Title: IntelliTamper HTML 'href' Parsing Buffer Overflow Vulnerability

Severity: HIGH

Description:

IntelliTamper is a spider application for scanning websites.

IntelliTamper is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.

This vulnerability occurs when the application parses HTML documents that contain overly large 'href' attributes. A URI consisting of at least 450 characters will trigger the issue. Attackers can exploit this issue by enticing a legitimate user to scan a malicious webpage.

This issue allows remote attackers to execute arbitrary machine code in the context of the application. Failed exploit attempts will likely crash the application, denying service to legitimate users.

IntelliTamper 2.07 is vulnerable; other versions may also be affected.

Affected Products:

  • IntelliTamper IntelliTamper 2.07

References: