Description
TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized ROM parameter to the tiemu command-line interface to overflow the stack buffer and overwrite the instruction pointer with malicious addresses.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
Juan Sacco - http://www.exploitpack.com -
References
www.exploit-db.com/exploits/39692 (ExploitDB-39692)
lpg.ticalc.org/prj_tiemu/ (Official Product Homepage)
www.vulncheck.com/...fsg-3-buffer-overflow-via-rom-parameter (VulnCheck Advisory: TiEmu 3.03-nogdb+dfsg-3 Buffer Overflow via ROM Parameter)