This application requires Javascript for optimal performance.

Green.Dam.URL.Processing.Buffer.Overflow

Release Date

Jul 07, 2009

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a stack-based overrun vulnerability in Green Dam, a web filter software mandated by the Chinese government.

The vulnerability is caused by an error when the vulnerable software handles a malformed URI. A remote attacker may exploit this to execute arbitrary code.

Affected Products

Green Dam v3.17 and prior

Recommended Actions

Currently we are not aware of any official patches for this issue.

Coverage

IPS
VCM

Reference/s

http://www.cse.umich.edu/~jhalderm/pub/gd/
http://www.securityfocus.com/bid/35435 (BugTraq)
http://www.milw0rm.com/exploits/8938
http://secunia.com/advisories/35435/

Reference: VID-17532