[Full-disclosure] Re: Buffer-overflow in [EMAIL PROTECTED] 1.0.1 viewer and server

2006-04-05 Thread Luigi Auriemma
[EMAIL PROTECTED] wrote: > Could you confirm my impression that the server vulnerability can only > overflow the buffer in 3 bytes? Yes, the buffer is overflowed just by those 3 bytes plus the Windows error message created with FormatMessage(). > Is there a way to exploit this for code executio

[Full-disclosure] Re: Buffer-overflow in [EMAIL PROTECTED] 1.0.1 viewer and server

2006-04-05 Thread jalvare7
Hello, Thank you for the disclosure of this issue. I'd like to better understand the extent of the problem, for which the code snippets have been very helpful, but I still would need some help in the case of the server vulnerability. Could you confirm my impression that the server vulnerabilit