vendor:
GNATS
by:
inv[at]dtors
7.5
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: GNATS
Affected Version From: GNATS 3.113.1_6
Affected Version To: GNATS 3.113.1_6
Patch Exists: YES
Related CWE: N/A
CPE: a:gnu:gnats:3.113.1_6
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 5.0
2004
GNATS queue-pr Stack Overflow Vulnerability
A stack overflow vulnerability has been reported for the queue-pr utility of GNATS. The vulnerability occurs due to insufficient checks performed on the arguments to the '-d' commandline option. Successful exploitation may result in the execution of attacker-supplied code with potentially elevated privileges.
Mitigation:
Ensure that all user-supplied input is validated and sanitized before being used.