PT-2008-2292 · Wintin+++1 · Wintin+++1
Luigi Auriemma
·
Published
2008-02-12
·
Updated
2018-10-15
·
CVE-2008-0671
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TinTin++ version 1.97.9
WinTin++ version 1.97.9
Description
The issue is related to a stack-based buffer overflow in the
add line buffer function, which can be triggered by remote attackers sending a long chat message. This overflow is connected to the conversion from LF to CRLF, allowing attackers to execute arbitrary code.Recommendations
For TinTin++ version 1.97.9, consider disabling the
add line buffer function until a patch is available to prevent exploitation.
For WinTin++ version 1.97.9, restrict the handling of long chat messages to minimize the risk of arbitrary code execution.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tintin++
Wintin++