Buffer Overflow Vulnerability in WideChapter Internet Browser for Windows

A vulnerability in WideChapter Internet Browser for Windows can result in the execution of arbitrary code on the vulnerable system.

Ken Pfeil

September 17, 2003

2 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported September 18, 2003, by Bahaa Naamneh.

 

 

VERSIONS AFFECTED

 

  • WideChapter Internet Browser for Windows

 

DESCRIPTION

 

A vulnerability in WideChapter Internet Browser for Windows can result in the execution of arbitrary code on the vulnerable system. By initiating a long HTTP request, an attacker can cause a buffer overflow in WideChapter. This overflow permits modification of the Execution Instruction Point, which lets the attacker execute arbitrary code.

 

DEMONSTRATION

 

The discoverer posted the following code as proof of concept:

 

By embedding the following JavaScript into a web page: < script>window.open(http://AAA.. [Ax517]), it is possible to cause the EIP to overwrite once a user visits the web page.

An exploit for Windows XP Home has created and is available for download from:http://www.elitehaven.net/wcexploit.zip

 

VENDOR RESPONSE

 

WideChapter has been notified.

 

CREDIT                                                                                                       
Discovered byBahaa Naamneh.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like