Home

Description

TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized ROM parameter to the tiemu command-line interface to overflow the stack buffer and overwrite the instruction pointer with malicious addresses.

PUBLISHED Reserved 2026-03-28 | Published 2026-03-28 | Updated 2026-04-01 | Assigner VulnCheck




HIGH: 8.6CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

3.03
affected

Credits

Juan Sacco - http://www.exploitpack.com - finder

References

www.exploit-db.com/exploits/39692 (ExploitDB-39692) exploit

lpg.ticalc.org/prj_tiemu/ (Official Product Homepage) product

www.vulncheck.com/...fsg-3-buffer-overflow-via-rom-parameter (VulnCheck Advisory: TiEmu 3.03-nogdb+dfsg-3 Buffer Overflow via ROM Parameter) third-party-advisory

cve.org (CVE-2016-20040)

nvd.nist.gov (CVE-2016-20040)

Download JSON