PT-2026-76737 · Unknown · Indiserver
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
indiserver versions prior to 2.2.4.3
Description
A stack buffer overflow occurs when the daemon processes malformed XML with mismatched tags exceeding 1024 bytes. An unauthenticated remote attacker can send a single TCP packet on port 7624 to trigger an unbounded
sprintf() write into a fixed 1024-byte stack buffer within MsgQueue.cpp. This action terminates the daemon and disrupts all active client and driver sessions.Recommendations
Update indiserver to the version containing commit 96bbd7f.
Exploit
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Indiserver