Heap Buffer Overflow in Sngrep Affects Multiple Versions by Irontec
CVE-2023-31982

7.8HIGH

Key Information:

Vendor

Irontec

Status
Vendor
CVE Published:
9 May 2023

What is CVE-2023-31982?

A heap buffer overflow vulnerability has been identified in Sngrep version 1.6.0. The issue arises in the capture_packet_reasm_ip function located in /src/capture.c. This flaw could potentially allow an attacker to execute arbitrary code, compromising the security of systems running this software. It is crucial for users to assess their systems and apply any necessary patches to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.