vendor:
Threaded USENET news reader
by:
Juan Sacco
7,5
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: Threaded USENET news reader
Affected Version From: 3.6-23
Affected Version To: 3.6-23
Patch Exists: YES
Related CWE: N/A
CPE: a:trn:threaded_usenet_news_reader:3.6-23
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux 2.0 x86
2020
TRN 3.6-23 Local Overflow Exploit
This exploit is a stack buffer overflow vulnerability in the Threaded USENET news reader version 3.6-23. It allows an attacker to execute arbitrary code by overflowing a buffer and overwriting the return address. The exploit uses a NOP sled, shellcode, and an EIP address to achieve this.
Mitigation:
The best way to mitigate this vulnerability is to upgrade to the latest version of the Threaded USENET news reader.