|
Brought to you by:
Suppliers of:
|
|
|
| |
| Grabit is a popular Windows usenet client designed for downloading binary files. It has support for NZB files, which a user would usually acquire from an external source. All versions 1.7.2 beta 3 and earlier of Grabit are vulnerable to a stack overflow when parsing DTD references in NZB files. |
| |
Credit:
The information has been provided by Niels Teusink.
The original article can be found at: http://blog.teusink.net/2009/05/grabit-172-beta-3-nzb-file-parsing.html
|
| |
Vulnerable Systems:
* Grabit version 1.7.2 beta 3 and all earlier versions
Patch Availability:
Grabit 1.7.2 beta 4, which fixes the bug. It can be downloaded at http://www.shemes.com/
|
|
|
|
|