PT-2014-2090 · Echoping · Echoping
Dmitry Semyonov
·
Published
2014-06-16
·
Updated
2014-06-17
·
CVE-2010-5111
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Echoping version 6.0.2
Description
The issue is related to multiple buffer overflows in the readline.c file, which can be exploited by remote attackers through crafted replies in the TLS readline or SSL readline functions. This can lead to a denial of service, causing the program to crash, and potentially allow the execution of arbitrary code.
Recommendations
For Echoping version 6.0.2, consider disabling the TLS readline and SSL readline functions as a temporary workaround until a patch is available. Restrict access to the readline.c module to minimize the risk of exploitation. Avoid using the affected functions in the EchoPingHttps Smokeping probe until the issue is resolved.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Echoping