Buffer Overflow Vulnerability in Samsung SmartThings Hub
CVE-2018-3863
9.9CRITICAL
What is CVE-2018-3863?
The Samsung SmartThings Hub STH-ETH-250 experiences a vulnerability where the video-core process fails to properly handle user-controlled JSON payloads. This improper extraction of fields can lead to a buffer overflow on the stack, specifically when a strcpy operation attempts to write to a buffer that exceeds its designated capacity of 40 bytes. An attacker can exploit this flaw by crafting an HTTP request with an excessively long 'user' value, thereby triggering the overflow and potentially allowing for unauthorized actions.
Affected Version(s)
SmartThings Hub STH-ETH-250 Firmware version 0.20.17