Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-36cw-x2xf-xmg3

Опубликовано: 28 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.4

Описание

SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets.

SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets.

EPSS

Процентиль: 9%
0.00194
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.4
nvd
5 месяцев назад

SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets.

CVSS3: 8.4
debian
5 месяцев назад

SIPP 3.3 contains a stack-based buffer overflow vulnerability that all ...

EPSS

Процентиль: 9%
0.00194
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-306