vendor:
sash
by:
lammat
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: sash
Affected Version From: sash-3.7
Affected Version To: sash-3.7
Patch Exists: NO
Related CWE:
CPE: a:sash:sash:3.7
Platforms Tested:
2005
sash-3.7 buffer overflow in c argyment
This exploit takes advantage of a buffer overflow vulnerability in sash-3.7. By providing a long string of 'A' characters as an argument to the program, it causes a segmentation fault and allows for arbitrary code execution. The exploit includes a shellcode that spawns a shell.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of sash.