PT-2008-2292 · Wintin+++1 · Wintin+++1

Luigi Auriemma

·

Published

2008-02-12

·

Updated

2018-10-15

·

CVE-2008-0671

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TinTin++ version 1.97.9 WinTin++ version 1.97.9
Description The issue is related to a stack-based buffer overflow in the add line buffer function, which can be triggered by remote attackers sending a long chat message. This overflow is connected to the conversion from LF to CRLF, allowing attackers to execute arbitrary code.
Recommendations For TinTin++ version 1.97.9, consider disabling the add line buffer function until a patch is available to prevent exploitation. For WinTin++ version 1.97.9, restrict the handling of long chat messages to minimize the risk of arbitrary code execution.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0671

Affected Products

Tintin++
Wintin++