PT-2026-85301 · Ui-Moos · Ui-Moos
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ui-moos versions prior to 50b9c6c
Description
A buffer overflow occurs in ScopeTabPane.cpp and ScopeGrid.cpp when client and variable names are formatted into fixed 1024-byte buffers using the
sprintf() function without length validation. An attacker can provide arbitrarily long MOOS identifiers that overflow these buffers when an operator selects process list entries or pokes variables, potentially leading to arbitrary code execution.Recommendations
Update ui-moos to a version later than 50b9c6c.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ui-Moos