vendor:
TORQUE Resource Manager
by:
bwall
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: TORQUE Resource Manager
Affected Version From: 2.5.x
Affected Version To: 2.5.13
Patch Exists: YES
Related CWE: CVE-2014-0749
CPE: 2.5.13
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Manjaro x64
2014
TORQUE Resource Manager 2.5.x-2.5.13 stack based buffer overflow stub
A buffer overflow while parsing the DIS network communication protocol is triggered when requesting that a larger amount of data than the small buffer be read. The first digit supplied is the number of digits in the data, the next digits are the actual size of the buffer. This exploit stub is meant to be a quick proof of concept and was built and tested for a 64 bit system with ASLR disabled. The result of this exploit is intended to just point RIP at 'exit()'.
Mitigation:
Update to the latest version of TORQUE Resource Manager.