vendor:
Netperf
by:
Juan Sacco
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Netperf
Affected Version From: 2.6.0
Affected Version To: 2.6.0
Patch Exists: YES
Related CWE: N/A
CPE: a:hewlettpackard:netperf:2.6.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali i686 GNU/Linux
2020
Netperf 2.6.0 – Segmentation Fault (PoC)
Netperf 2.6.0 is a benchmark tool developed by Hewlett Packard that can be used to measure the performance of many different types of networking. It provides tests for both unidirectional throughput and end-to-end latency. A buffer overflow vulnerability exists in the program, which can be exploited by an attacker to execute arbitrary code on the target system. The attacker can craft a malicious payload with a length of 8220 bytes, followed by the address 0x41424344, which will overwrite the EIP register and cause a segmentation fault. This can be used to gain control of the program flow and execute arbitrary code.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of the software.