Local Buffer Overflow Vulnerability in PInfo by Alioth
CVE-2016-20044
Key Information:
Badges
What is CVE-2016-20044?
PInfo version 0.6.9-5.1 is susceptible to a local buffer overflow vulnerability that can be exploited by local attackers. By providing an oversized argument to the -m parameter, attackers can manipulate the program's execution flow. This is achieved by crafting a malicious input string that contains 564 bytes of padding, followed by a return address, allowing the attacker to overwrite the instruction pointer. Successful exploitation enables execution of arbitrary shellcode with user privileges, representing a significant risk to system integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PInfo 0.6.9-5.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
