Free Newsletters

   All InfoWorld Newsletters
Security Adviser | Roger A. Grimes » Buffer Overflow in Visual Studio and InterDev

March 05, 2006 | Comments: (0)

Buffer Overflow in Visual Studio and InterDev

FRSIRT announces Buffer Overflow in Visual Studio and InterDev

http://www.frsirt.com/english/advisories/2006/0825

A vulnerability has been identified in Microsoft Visual Studio and Microsoft Visual InterDev, which could be exploited by attackers to execute arbitrary commands. This flaw is due to a buffer overflow error when processing specially crafted Database Project (.dbp) or Solution (.sln) files containing an overly long "DataProject" field, which could be exploited by attackers to compromise a vulnerable system by tricking a user into opening a malicious ".dbp" or ".sln" file.

No patch available. No a critical buffer overflow, but interesting nonetheless.

Posted by Roger Grimes on March 5, 2006 12:45 PM


RATE THIS ARTICLE:





 

  •  
  • COMMENTS




Followed by exploit code.

http://www.frsirt.com/exploits/20060305.ms-visual-dbp.c.php

Posted by: Roger A. Grimes at March 5, 2006 04:45 PM

Technology White Papers

 

InfoWorld Technology Marketplace

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
» BUY A LINK NOW

Sponsored Technology Links