vendor:
Expect
by:
isox
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Expect
Affected Version From: 5.28.1
Affected Version To: 5.31.8
Patch Exists: YES
Related CWE: N/A
CPE: a:tcl:expect
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Slackware 7.x
2000
Expect Buffer Overflow
This exploit is a buffer overflow vulnerability in the expect program. It was tested on versions 5.31.8 and 5.28.1 of expect, running on Slackware 7.x. The exploit uses a NOP sled and shellcode to overwrite the return address of the stack frame, allowing the attacker to execute arbitrary code.
Mitigation:
The best way to mitigate this vulnerability is to upgrade to the latest version of expect, which should contain a patch for this vulnerability.