vendor:
Sniffit
by:
FuSyS [S0ftpj|BFi]
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Sniffit
Affected Version From: 0.3.7beta
Affected Version To: 0.3.7beta
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux/x86
2000
Sniffit 0.3.7beta Linux/x86 Remote Exploit
Sniffit is a freely available, open source network monitoring tool designed for use on the Unix and Linux Operating Systems. Sniffit contains a remotely exploitable buffer overflow vulnerability. If Sniffit is configured to log emails, attackers may be able to exploit a stack overflow in the logging mechanism and execute arbitrary code as root on the underlying host.
Mitigation:
Administrators are advised to use more actively supported alternatives such as Snort or dsniff.