vendor:
Mini-stream Ripper
by:
Hazem Mofeed
7,2
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: Mini-stream Ripper
Affected Version From: 3.1.0.8
Affected Version To: 3.1.0.8
Patch Exists: Yes
Related CWE: N/A
CPE: a:mini-stream:mini-stream_ripper
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Mini-stream Ripper 3.1.0.8 => Local stack overflow exploit
Mini-stream Ripper 3.1.0.8 is vulnerable to a local stack overflow vulnerability. By sending a specially crafted .smi file, an attacker can overwrite the return address of the stack and execute arbitrary code. The exploit code contains a shellcode that spawns a shell on port 4444.
Mitigation:
Upgrade to the latest version of Mini-stream Ripper.