PT-2011-2745 · Tsclient · Tsclient
D3V!L Fucker
·
Published
2011-02-07
·
Updated
2017-08-17
·
CVE-2011-0900
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Terminal Server Client (tsclient) versions 0.150 and possibly other versions
Description
The issue is a stack-based buffer overflow in the tsc launch remote function, located in the src/support.c file. This allows user-assisted remote attackers to execute arbitrary code via a .RDP file with a long hostname argument.
Recommendations
For version 0.150, update to a version that fixes the stack-based buffer overflow issue in the tsc launch remote function.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tsclient