Vulnerability Description
iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized value to the -k/--key parameter. Attackers can craft a malicious argument containing a NOP sled, shellcode, and return address to overflow a 1024-byte stack buffer and gain code execution with user privileges.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://www.ossp.org/pkg/tool/iselect/
- https://www.exploit-db.com/exploits/41076
- https://www.vulncheck.com/advisories/iselect-2-b1-local-buffer-overflow-via-key-
FAQ
What is CVE-2016-20048?
CVE-2016-20048 is a vulnerability with a CVSS score of 8.4 (HIGH). iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized value to the -k/--key parameter. Attackers can craft a...
How severe is CVE-2016-20048?
CVE-2016-20048 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-20048?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.