PT-2011-5197 · Torcs+4 · Torcs+4

Andrés Gómez

·

Publicado

1970-01-01

·

Atualizado

2016-08-02

·

CVE-2011-4620

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PLIB version 1.8.5 TORCS version 1.3.1 plib-devel (affected versions not specified) plib (affected versions not specified) plib-debuginfo (affected versions not specified) plib-debugsource (affected versions not specified)
Description The issue involves a buffer overflow in the ulSetError function in util/ulError.cxx in PLIB, which can be exploited by remote attackers to execute arbitrary code via vectors involving a long error message. This can be demonstrated by a crafted acc file for TORCS. Additionally, multiple vulnerabilities in the plib package in openSUSE and Debian GNU/Linux operating systems can lead to disruption of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For PLIB version 1.8.5, consider disabling the ulSetError function until a patch is available. For TORCS version 1.3.1, avoid using crafted acc files that can trigger the buffer overflow in the ulSetError function. For plib-devel, plib, plib-debuginfo, and plib-debugsource, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01749
BDU:2015-05406
BDU:2015-05407
BDU:2015-05408
BDU:2015-05409
CVE-2011-4620
DSA-2425-1
OPENSUSE-SU-2012_1506-1
OPENSUSE-SU-2013_0146-1
OPENSUSE-SU-2024:10308-1

Produtos afetados

Debian
Plib
Suse
Torcs
Opensuse