Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-5439

Опубликовано: 19 нояб. 2019
Источник: debian

Описание

Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout randomization ASLR protection mechanisms, which could let a malicious user execute arbitrary code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sniffitfixed0.3.7.beta-20package
sniffitfixed0.3.7.beta-17+deb8u1jessiepackage

Примечания

  • http://hmarco.org/bugs/CVE-2014-5439-sniffit_0.3.7-stack-buffer-overflow.html

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout randomization ASLR protection mechanisms, which could let a malicious user execute arbitrary code.

CVSS3: 7.8
nvd
около 6 лет назад

Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout randomization ASLR protection mechanisms, which could let a malicious user execute arbitrary code.

CVSS3: 7.8
github
больше 3 лет назад

sniffit 0.3.7 and prior: A configuration file can be leveraged to execute code as root