First published: Tue Dec 27 2011(Updated: )
The IDAPython plugin before 1.5.2.3 in IDA Pro allows user-assisted remote attackers to execute arbitrary code via a crafted IDB file, related to improper handling of certain swig_runtime_data files in the current working directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Idapython | <=1.5.2 | |
Google Idapython | =1.2.0 | |
Google Idapython | =1.4.0 | |
Google Idapython | =1.4.1 | |
Google Idapython | =1.4.2 | |
Google Idapython | =1.4.3 | |
Google Idapython | =1.5.0 | |
Google Idapython | =1.5.1 | |
Hex-Rays IDA | =6.0 |
http://code.google.com/p/idapython/downloads/detail?name=idapython-1.5.2.3_ida6.1_py2.6_win32.zip
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.