PMS 0.42 Stack-Based Buffer Overflow via Configuration File
Vulnerability Description
PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via return-oriented programming gadgets.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25224
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Juan Sacco <jsacco@exploitpack.com> - http://exploitpack.com