Vulnerability Description
Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jpchacha | Chasys Draw Ies | <= 4.10.01 |
Related Weaknesses (CWE)
References
- http://longinox.blogspot.com/2013/08/explot-stack-based-overflow-bypassing.html
- http://packetstormsecurity.com/files/122810/Chasys-Draw-IES-Buffer-Overflow.htmlExploit
- http://secunia.com/advisories/53773Vendor Advisory
- http://www.exploit-db.com/exploits/27609Exploit
- http://www.jpchacha.com/chasysdraw/help.php?file=history.htm
- http://www.securityfocus.com/bid/61463
- https://docs.google.com/file/d/0BzyiGAtMizMtSFF4ZWVCMHNVVGs/edit?usp=sharing
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86035
- http://longinox.blogspot.com/2013/08/explot-stack-based-overflow-bypassing.html
- http://packetstormsecurity.com/files/122810/Chasys-Draw-IES-Buffer-Overflow.htmlExploit
- http://secunia.com/advisories/53773Vendor Advisory
- http://www.exploit-db.com/exploits/27609Exploit
- http://www.jpchacha.com/chasysdraw/help.php?file=history.htm
- http://www.securityfocus.com/bid/61463
- https://docs.google.com/file/d/0BzyiGAtMizMtSFF4ZWVCMHNVVGs/edit?usp=sharing
FAQ
What is CVE-2013-3928?
CVE-2013-3928 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a ...
How severe is CVE-2013-3928?
CVE-2013-3928 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3928?
Check the references section above for vendor advisories and patch information. Affected products include: Jpchacha Chasys Draw Ies.