vendor:
nipper-ng
by:
Guy Levin
7.8
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: nipper-ng
Affected Version From: 2000.11.10
Affected Version To: 2000.11.10
Patch Exists: NO
Related CWE: CVE-2019-17424
CPE: cpe:2.3:a:nipper-ng:nipper-ng:0.11.10
Platforms Tested: Debian
2019
nipper-ng 0.11.10 โ Remote Buffer Overflow (PoC)
This is a proof-of-concept exploit for a remote buffer overflow vulnerability in nipper-ng version 0.11.10. The vulnerability was found by Guy Levin and can be exploited by sending a specially crafted shell command. The exploit uses a buffer overflow to overwrite the return address and gain control of the program execution flow. The vulnerability is tracked as CVE-2019-17424.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of nipper-ng.