This application requires Javascript for optimal performance.

GAlan.Galan.File.Stack.Overflow

Release Date

Dec 29, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a remote code-execution vulnerability in gAlan.

The vulnerability is caused by an error when handling malformed gAlan files (.galan). It can be exploited via a crafted gAlan file, leading to remote code execution.

Affected Products

gAlan 0.2.1

Recommended Actions

Currently we are not aware of any officially supplied patch for this issue.

Coverage

IPS
VCM

Reference/s

http://www.exploit-db.com/exploits/10339

Reference: VID-18034