CVE-2009-3276

Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many alphabetic characters followed by a ! (exclamation point), related to a certain regular expression, aka a "ReDoS" vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nasd:corenet1:1.2:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.7:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.8:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.9:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.10:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.12:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.13:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.15:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.17:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.18:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.19:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:1.24:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.7:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.8:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.9:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.11:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.12:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.13:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.14:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.15:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.16:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.17:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.18:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:2.19:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:3.2:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:3.11:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:3.12:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:3.13:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:3.14:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:3.15:*:*:*:*:*:*:*
cpe:2.3:a:nasd:corenet1:3.16:*:*:*:*:*:*:*

History

21 Nov 2024, 01:06

Type Values Removed Values Added
References () http://www.checkmarx.com/Upload/Documents/PDF/Checkmarx_OWASP_IL_2009_ReDoS.pdf - Exploit () http://www.checkmarx.com/Upload/Documents/PDF/Checkmarx_OWASP_IL_2009_ReDoS.pdf - Exploit
References () http://www.securityfocus.com/archive/1/506419/100/0/threaded - () http://www.securityfocus.com/archive/1/506419/100/0/threaded -

Information

Published : 2009-09-21 19:30

Updated : 2025-04-09 00:30


NVD link : CVE-2009-3276

Mitre link : CVE-2009-3276

CVE.ORG link : CVE-2009-3276


JSON object : View

Products Affected

nasd

  • corenet1