Описание
Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout randomization ASLR protection mechanisms, which could let a malicious user execute arbitrary code.
Ссылки
- ExploitPatchThird Party AdvisoryVDB Entry
- ExploitPatchThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Одно из
EPSS
7.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout randomization ASLR protection mechanisms, which could let a malicious user execute arbitrary code.
Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit ...
sniffit 0.3.7 and prior: A configuration file can be leveraged to execute code as root
EPSS
7.8 High
CVSS3
9.3 Critical
CVSS2