Description
Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized argument to the -p parameter. Attackers can invoke yasr with a crafted payload containing junk data, shellcode, and a return address to overwrite the stack and trigger code execution.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
Juan Sacco - http://www.exploitpack.com - jsacco@exploitpack.com, Juan Sacco"
References
www.exploit-db.com/exploits/39734 (ExploitDB-39734)
yasr.sourceforge.net/ (Official Product Homepage)
www.vulncheck.com/...fer-overflow-via-command-line-parameter (VulnCheck Advisory: Yasr 0.6.9-5 Buffer Overflow via Command-line Parameter)