Logica HotScan SWIFT Alliance Access Interface BufferOverflow Vulnerability
23 Oct. 2012
Summary
Hotscan Listener interface is prone to buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input. This allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file
Credit:
The information has been provided by Anil Pazvant.
By sending malicious input to hotscan listener tcp interface, it is possible to overwrite stack only by two bytes. The software compiled with NXCOMPAT, Code execution could not be done. Therefore crash of this service can stop all swift process , this effects the impact of vulnerability.