9.3

CVE-2011-4783

The IDAPython plugin before 1.5.2.3 in IDA Pro allows user-assisted remote attackers to execute arbitrary code via a crafted IDB file, related to improper handling of certain swig_runtime_data files in the current working directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Idapython Version <= 1.5.2
   Hex-rays ≫ Ida Version 6.0 Edition pro
Google ≫ Idapython Version 1.2.0
   Hex-rays ≫ Ida Version 6.0 Edition pro
Google ≫ Idapython Version 1.4.0
   Hex-rays ≫ Ida Version 6.0 Edition pro
Google ≫ Idapython Version 1.4.1
   Hex-rays ≫ Ida Version 6.0 Edition pro
Google ≫ Idapython Version 1.4.2
   Hex-rays ≫ Ida Version 6.0 Edition pro
Google ≫ Idapython Version 1.4.3
   Hex-rays ≫ Ida Version 6.0 Edition pro
Google ≫ Idapython Version 1.5.0
   Hex-rays ≫ Ida Version 6.0 Edition pro
Google ≫ Idapython Version 1.5.1
   Hex-rays ≫ Ida Version 6.0 Edition pro
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.4% 0.904
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://code.google.com/p/idapython/downloads/detail?name=idapython-1.5.2.3_ida6.1_py2.6_win32.zip
Patch
http://code.google.com/p/idapython/source/detail?r=361
http://secunia.com/advisories/47295
Vendor Advisory
http://technet.microsoft.com/en-us/security/msvr/msvr11-015
https://exchange.xforce.ibmcloud.com/vulnerabilities/71936