20040717 [FMADV] Format String Bug in OllyDbg 1.10mailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0711.html CVE-2004-0733
OllyDbg 1.10 - Local Format String
Record summary
CVE-2004-0733 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are directly provided to the OutputDebugString function call.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBOllyDbg 1.10 - Local Format StringExploitDB exploitby jamikazuNot analyzed1 file
ExploitDBOllyDbg 1.10 - Format StringExploitDB exploitby Ahmet CihanNot analyzed1 file
References
620040717 [FMADV] Format String Bug in OllyDbg 1.10mailing list
http://marc.info/?l=bugtraq&m=109007978822810&w=2 10742vdb entry
http://www.securityfocus.com/bid/10742 ollydbg-outputdebugstring-format-string(16711)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16711 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0733 3757exploit
https://www.exploit-db.com/exploits/3757