SIPP 3.3 Stack-Based Buffer Overflow via Configuration File
Vulnerability Description
SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25225
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Juan Sacco <jsacco@exploitpack.com> - http://exploitpack.com
References
Affected Vendor
Sipp
View all reports →