Description
CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious M3U playlist file with 536 bytes of buffer and shellcode to trigger remote code execution.
Problem types
Product status
16.01
Credits
T3jv1l
References
www.exploit-db.com/exploits/48344 (ExploitDB-48344)
www.codeblocks.org/ (CODE::BLOCKS Product Homepage)
sourceforge.net/projects/codeblocks/ (CODE::BLOCKS SourceForge Repository)
www.vulncheck.com/.../codeblocks-buffer-overflow-seh-unicode (VulnCheck Advisory: CODE::BLOCKS 16.01 - Buffer Overflow (SEH) UNICODE)