PT-2023-29319 · Unknown · Easy Chat Server
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Easy Chat Server version 3.1
Description
A stack-based buffer overflow issue exists due to an excessively long
username string being sent to the "register.ghp" file via a GET request, potentially leading to arbitrary code execution on the remote machine.Recommendations
For Easy Chat Server version 3.1, consider restricting access to the "register.ghp" file to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the length of the
username string to prevent buffer overflow.Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Easy Chat Server