Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-892q-pfj4-43mq

Опубликовано: 22 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.4

Описание

Axessh 4.2 contains a stack-based buffer overflow vulnerability in the log file name field that allows local attackers to execute arbitrary code by supplying an excessively long filename. Attackers can overflow the buffer at offset 214 bytes to overwrite the instruction pointer and execute shellcode with system privileges.

Axessh 4.2 contains a stack-based buffer overflow vulnerability in the log file name field that allows local attackers to execute arbitrary code by supplying an excessively long filename. Attackers can overflow the buffer at offset 214 bytes to overwrite the instruction pointer and execute shellcode with system privileges.

EPSS

Процентиль: 4%
0.00018
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.4
nvd
24 дня назад

Axessh 4.2 contains a stack-based buffer overflow vulnerability in the log file name field that allows local attackers to execute arbitrary code by supplying an excessively long filename. Attackers can overflow the buffer at offset 214 bytes to overwrite the instruction pointer and execute shellcode with system privileges.

EPSS

Процентиль: 4%
0.00018
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-787