PT-2016-7990 · Debian+2 · Pinfo

Published

2016-01-01

·

Updated

2026-03-28

·

CVE-2016-20044

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PInfo versions 0.6.9 through 0.6.9-5.1
Description PInfo versions 0.6.9 through 0.6.9-5.1 contain a local buffer overflow vulnerability. Local attackers can execute arbitrary code by providing an oversized argument to the -m parameter. Attackers can create a malicious input string with 564 bytes of padding followed by a return address to overwrite the instruction pointer and execute shellcode with user privileges.
Recommendations PInfo version 0.6.9-5.1: Avoid providing oversized arguments to the -m parameter.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2016-20044

Affected Products

Pinfo