Motorola Timbuktu PlughNTCommand Buffer Overflow

Strike ID:
E13-2ro01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2013

Description

This strike exploits a buffer overflow vulnerability in the Motorola Timbuktu product. A boundary error exists when handling the pipe PlughNTCommand. The format is Integer SP Ip Address SP Integer SP String1 SP String2, The destination buffers are allocated from stack with fixed size, and if given a 9 the code uses a scanf type function to parse the payload with the format %hd %s %hd %s %s. If an overly long string is given for the IP address, String1 or String2 the buffer will be overrun.

CVE

Bid