Stack-based Buffer Overflow in Arm Whois by Arm Holdings
CVE-2018-25427
Key Information:
Badges
What is CVE-2018-25427?
Arm Whois version 3.11 contains a stack-based buffer overflow that can be exploited by remote attackers to execute arbitrary code. By providing oversized input exceeding 658 bytes in the IP address or domain field, attackers can leverage this flaw to overwrite the structured exception handler, ultimately gaining command execution rights when the application processes their input. This vulnerability highlights the importance of input validation and secure coding practices to prevent unauthorized access and potential system compromise.
Affected Version(s)
Arm Whois 3.11
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
