vendor:
Web Server
by:
Damian Myerscough
7.5
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: Web Server
Affected Version From: web_server-0.0.5
Affected Version To: web_server-0.0.6
Patch Exists: YES
Related CWE: N/A
CPE: //a:wsmp3:web_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: RedHat Linux 6.x
2002
Remote Heap malloc/free & multiple Overflow vulnerability in WSMP3
A remotely exploitable heap corruption vulnerability has been reported for WSMP3. Due to insufficient bounds checking of user-supplied input, it is possible for a remote attacker to corrupt heap memory. By corrupting allocated memory headers, it is possible to redirect program flow when the free() function is called. Successful exploitation of this issue may result in remote execution of arbitrary code with root privileges.
Mitigation:
Apply the latest security patches and updates to the system.