vendor:
Gadu
by:
Juan Sacco
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Gadu
Affected Version From: 1:1.9~pre+r2855-3+b1
Affected Version To: 1:1.9~pre+r2855-3+b1
Patch Exists: YES
Related CWE: N/A
CPE: ekg
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux 2.0 x86
2020
Exploit EKG Gadu – Local Overflow Exploit
EKG Gadu is an open source Gadu-Gadu client for UNIX systems. This exploit uses a buffer overflow vulnerability to execute arbitrary code on the target system. The exploit is developed using Exploit Pack v6.01 and tested on Kali Linux 2.0 x86. The vulnerable program is EKG Gadu version 1:1.9~pre+r2855-3+b1. The exploit uses a NOPSLED + SHELLCODE + EIP payload to execute arbitrary code on the target system.
Mitigation:
Update to the latest version of EKG Gadu.