vendor:
Frigate
by:
Paras Bhatia
7.5
CVSS
HIGH
Local Buffer Overflow
119
CWE
Product Name: Frigate
Affected Version From:
Affected Version To: 3.36.0.9
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 Ultimate Service Pack 1 (32 bit - English)
2020
Frigate 3.36.0.9 – ‘Command Line’ Local Buffer Overflow (SEH) (PoC)
This exploit demonstrates a local buffer overflow vulnerability in Frigate version 3.36.0.9. By pasting a specially crafted input into the 'Command Line' field of the Frigate application, an attacker can execute arbitrary code and gain control of the system. This exploit triggers the execution of the calc.exe program as a proof of concept.
Mitigation:
The vendor should release a patch to address the buffer overflow vulnerability in Frigate. In the meantime, users can mitigate the risk by ensuring that the Frigate application is not accessible to untrusted sources and by implementing proper input validation and boundary checks.