Note:
This project will be discontinued after December 13, 2021. [more]
2017-03-16
Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or possibly have unspecified other impact via a large value.
Products | Capstone |
Type | Integer Overflow or Wraparound (CWE-190) |
First patch |
https://github.com/aquynh/capstone/commit/6fe86eef621b9849f51a5e1e5d73258a93440403 |
Relevant file/s | ./windows/winkernel_mm.c (modified, +11, -2) |
Links | http://www.securityfocus.com/bid/97323 |
Navigation
Patch data:
Patched area:
(on by default)
Patched area: