vendor:
Splitvt
by:
Syzop
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Splitvt
Affected Version From: 1.6.2003
Affected Version To: 1.6.3-4
Patch Exists: YES
Related CWE: N/A
CPE: a:splitvt:splitvt:1.6.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2001
Buffer Overflow in Splitvt 1.6.3 and Earlier
A buffer overflow condition exists in splitvt 1.6.3 and earlier. Splitvt is distributed with several Linux distributions. An attacker can exploit this vulnerability to obtain root access. The exploit code is written in C and uses a NOP sled and static pointer to /bin/sh to execute the shellcode.
Mitigation:
Upgrade to the latest version of splitvt