Description
ZOC Terminal 7.23.4 contains a buffer overflow vulnerability in the Shell field of Program Settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a crafted payload into the Shell configuration field and trigger a crash when accessing the Command Shell feature.
Problem types
Product status
Credits
Victor Mondragón
References
www.exploit-db.com/exploits/46857 (ExploitDB-46857)
www.emtec.com (Official Product Homepage)
www.emtec.com/downloads/zoc/zoc7234_x64.exe (Product Reference)
www.vulncheck.com/...minal-buffer-overflow-denial-of-service (VulnCheck Advisory: ZOC Terminal 7.23.4 Buffer Overflow Denial of Service)