C# Exceptions



Hi,

I'm testing a C# desktop application. During my testing so far we have
found security issues that lead to application crash with following
type of errors:

1. Acess Violation Acception
2. Null Reference Acception
3. Invalid Object Acception
4. Application crash dump

Are these issues really a security threat for a desktop application?

We got these errors by sending junk data over the network replies that
this application gets from its web services. However I fail to
understand the security implication and risk of these exceptions.
Since this is a desktop application and not a web service or server
how would these issues impact the security of the desktop application.
The application doesn't open any port on the network for incoming
requests. What would be the best strategy to test such application?
What would be the points from where attacker could attack such a
aplication.

I'll really appreciate some enlightening thoughts on above queries.

Thanx in advance.

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php
------------------------------------------------------------------------



Relevant Pages

  • [NT] Trillian Remote DoS (Malformed TypingUser)
    ... Beyond Security in Canada ... * Trillian version 1.0 Pro ... It is possible to crash Trillian by sending a corrupt 'TypingUser' ...
    (Securiteam)
  • Re: Linux 2.6.29
    ... else's old data in my file - a serious security issue. ... the metadata is updated, leaving the data written by some other ... this guarantee means that a crash is not likely to scramble your entire disk, but any data written shortly before the crash may not have made it to disk. ... XFS and ext4 solve the problem by not allocating the data blocks until they are actually ready to write the data. ...
    (Linux-Kernel)
  • Re: [Full-Disclosure] [Advisory] Mozilla Products Remote Crash Vulnerability
    ... This crash was fixed today. ... FYI - simple unexploitable crashes are generally not considered security ... Things are different for server products, and some parts of the Mozilla ... This does not mean crashes will be ignored and will go unfixed. ...
    (Full-Disclosure)
  • [ GLSA 200407-08 ] Ethereal: Multiple security problems
    ... which may allow an attacker to run arbitrary code or crash ... Ethereal is a feature rich network protocol analyzer. ... There are multiple vulnerabilities in versions of Ethereal earlier than ... Security is a primary focus of Gentoo Linux and ensuring the ...
    (Full-Disclosure)
  • [Full-Disclosure] [ GLSA 200407-08 ] Ethereal: Multiple security problems
    ... which may allow an attacker to run arbitrary code or crash ... Ethereal is a feature rich network protocol analyzer. ... There are multiple vulnerabilities in versions of Ethereal earlier than ... Security is a primary focus of Gentoo Linux and ensuring the ...
    (Full-Disclosure)