vendor:
Scite
by:
kmkz
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Scite
Affected Version From: 1.76
Affected Version To: 1.76
Patch Exists: YES
Related CWE: N/A
CPE: a:scite:scite
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2010
Scite text editor :Local Buffer Overflow (PoC)
This PoC generates a .txt document and crashes Scite exploiting a local Buffer Overflow. The exploit uses a payload of 4092 A characters followed by 4 NOP instructions. The exploit is tested on Linux 2.6.31-22 and is applicable to Scite version 1.76.
Mitigation:
Ensure that the latest version of Scite is installed and that all security patches are applied.