[NT] Microsoft NetMeeting Null Pointer
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 11 Jun 2006 14:17:37 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Microsoft NetMeeting Null Pointer
------------------------------------------------------------------------
SUMMARY
" <http://www.microsoft.com/windows/netmeeting/> Microsoft NetMeeting is
an application that provides multipoint audio/video conferencing and
supporting services (desktop sharing, whiteboard, remote control, file
transfer) for Microsoft Windows platform."
Improper validation of user input allows attackers to execute arbitrary
code using null pointer access.
DETAILS
Vulnerable Systems:
* Microsoft NetMeeting version 3.01
The application insufficiently validates received data opening a
possibility to overwrite portions of application memory causing exceptions
ranging from null-pointer access to a possible code execution. It is
possible to remotely terminate an active NetMeeting presentation by either
crashing the hosting application or causing it to consume 100% of CPU
resources.
ADDITIONAL INFORMATION
The information has been provided by <mailto:vuln@xxxxxxxxxxx> hexview..
The original article can be found at:
<http://www.hexview.com/docs/20060606-1.txt>
http://www.hexview.com/docs/20060606-1.txt
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NEWS] Multiple Browsers File Upload Data Disclosure
- Next by Date: [NEWS] D-Link DWL-2100ap Information Disclosure
- Previous by thread: [NEWS] Multiple Browsers File Upload Data Disclosure
- Next by thread: [NEWS] D-Link DWL-2100ap Information Disclosure
- Index(es):
Relevant Pages
|