|
THQ's Yager contains a flaw that may allow a malicious user to remotely execute malicious code with the privileges of the user running the application. The issue is due to the application failing to properly validate the length of user-supplied, network derived data blocks with a maximum size of 65536 bits prior to copying them into a static buffer with a maximum size of 256 bytes. It is possible that the flaw may allow privilege escalation or unauthorized access resulting in a loss of confidentiality and/or integrity.
|