PT-2011-5197 · Torcs+4 · Torcs+4

Andrés Gómez

·

Published

1970-01-01

·

Updated

2016-08-02

·

CVE-2011-4620

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PLIB version 1.8.5 TORCS version 1.3.1 plib-devel (affected versions not specified) plib (affected versions not specified) plib-debuginfo (affected versions not specified) plib-debugsource (affected versions not specified)
Description The issue involves a buffer overflow in the ulSetError function in util/ulError.cxx in PLIB, which can be exploited by remote attackers to execute arbitrary code via vectors involving a long error message. This can be demonstrated by a crafted acc file for TORCS. Additionally, multiple vulnerabilities in the plib package in openSUSE and Debian GNU/Linux operating systems can lead to disruption of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For PLIB version 1.8.5, consider disabling the ulSetError function until a patch is available. For TORCS version 1.3.1, avoid using crafted acc files that can trigger the buffer overflow in the ulSetError function. For plib-devel, plib, plib-debuginfo, and plib-debugsource, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01749
BDU:2015-05406
BDU:2015-05407
BDU:2015-05408
BDU:2015-05409
CVE-2011-4620
DSA-2425-1
OPENSUSE-SU-2012_1506-1
OPENSUSE-SU-2013_0146-1
OPENSUSE-SU-2024:10308-1

Affected Products

Debian
Plib
Suse
Torcs
Opensuse