[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : GetRight <= 5.2a Skin File (*.grs) Buffer Overflow Exploit
# Published : 2004-12-06
# Author : ATmaCA
# Previous Title : Battlefield 1942 <= 1.6.19 and Vietnam <= 1.2 Broadcast Client Crash
# Next Title : Kreed <= 1.05 Format String and Denial of Service Exploit


GetRight Skin File (*.grs) Buffer Overflow May Let Remote Users Run Arbitrary
Code

Application:  GetRight
             Headlight Software
             www.getright.com

Author:
ATmaCA <atmaca@prohack.net>

a remote user can create a malicious skin file (*.grs) that, when loaded by the
target user, will trigger a buffer overflow in DUNZIP32.DLL (4.0.0.3) and
potentially execute arbitrary code.

AFFECTED VERSION:
Versions verified to be vulnerable:
GetRight 5.2a and prior versions are affected.

Solutions:
There was no response.

Exploit:
http://www.milw0rm.com/sploits/c_skin.grs
When you copy or click this link, getright automaticly download and try to load
crafted skin and will trigger buffer overflow

# www.Syue.com [2004-12-06]