Description
TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can trigger the overflow through command-line arguments passed to the application, leveraging ROP gadgets to bypass protections and execute shellcode in the application context.
Problem types
Product status
Credits
Juan Sacco <juan.sacco@kpn.com> at KPN Red Team - http://www.kpn.com
References
www.exploit-db.com/exploits/42087 (ExploitDB-42087)
lpg.ticalc.org/prj_tiemu/ (Official Product Homepage)
www.vulncheck.com/...ack-based-buffer-overflow-vulnerability (VulnCheck Advisory: TiEmu 2.08 Stack-Based Buffer Overflow Vulnerability)