vendor:
typespeed
by:
Javier Kohen
7.2
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: typespeed
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2003
typespeed Local Format String Vulnerability
typespeed is prone to a local format string vulnerability. Successful exploitation could allow privilege escalation. The exploit uses a proof of concept local exploit for typespeed tool. It sets the environment variable HOME to a buffer containing the address of the variable var, which is then used to overwrite the return address of the main function with the address of the shellcode. The exploit then calls the typespeed tool, which executes the shellcode.
Mitigation:
Upgrade to the latest version of typespeed.