20061012 Google Earth (kml & kmz files) buffer overflowmailing list
http://marc.info/?l=full-disclosure&m=116068034629718&w=2 CVE-2006-7157
Google Earth 4.0.2091 (Beta) - '.KML'/'.KMZ' Buffer Overflow
Record summary
CVE-2006-7157 has a selected CVSS score of 7.1; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with a long href element.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGoogle Earth 4.0.2091 (Beta) - '.KML'/'.KMZ' Buffer OverflowExploitDB exploitby JAAScoisNot analyzed1 file
References
7securitydot.net
http://securitydot.net/xpl/exploits/vulnerabilities/articles/1660/exploit.html 2375Third-party advisory
http://securityreason.com/securityalert/2375 20061012 Google Earth (kml & kmz files) buffer overflowmailing list
http://www.securityfocus.com/archive/1/448544/100/0/threaded 20464vdb entry
http://www.securityfocus.com/bid/20464 google-earth-kml-kmz-bo(29502)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/29502 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-7157