The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to obtain sensitive information via a URI with a % (percent) character as its (1) last or (2) second-to-last character, in situations where a certain "post-URL data" buffer contains a 0x0000 character but a buffer overflow does not occur.
Advisories
Source ID Title
EUVD EUVD EUVD-2012-2406 The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to obtain sensitive information via a URI with a % (percent) character as its (1) last or (2) second-to-last character, in situations where a certain "post-URL data" buffer contains a 0x0000 character but a buffer overflow does not occur.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T19:34:25.214Z

Reserved: 2012-04-25T00:00:00

Link: CVE-2012-2420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-04-25T20:55:01.293

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-2420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses