vendor:
word-list-compress
by:
c0d3r / root
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: word-list-compress
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
word-list-compress Local Exploit
This is a local exploit for the word-list-compress program. It takes advantage of a buffer overflow vulnerability to execute arbitrary code. The exploit overflows the exploit buffer with a shellcode and sets the return address to a specific address in memory. It then loads the exploit string into the environment and executes the word-list-compress program with the exploit as an argument.
Mitigation:
The vulnerability can be mitigated by updating the word-list-compress program to fix the buffer overflow vulnerability.