PT-2004-1579 · Vice Team · Vice
Published
2004-06-24
·
Updated
2017-07-11
·
CVE-2004-0453
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VICE versions 1.6 through 1.14
Description
The issue is related to a format string vulnerability in the monitor "memory dump" command. This vulnerability can be exploited by local users to cause a denial of service, potentially leading to an emulator crash. It may also be possible for attackers to execute arbitrary code via format string specifiers in an output string.
Recommendations
For VICE versions 1.6 through 1.14, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vice