Description
Echo Mirage 3.1 contains a stack buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized string in the Rules action field. Attackers can create a malicious text file with a crafted payload exceeding buffer boundaries and paste it into the action field through the Rules dialog to trigger the overflow and overwrite the return address.
Problem types
Product status
Credits
InitD Community
References
www.exploit-db.com/exploits/46216 (ExploitDB-46216)
initd.sh/ (Official Product Homepage)
sourceforge.net/projects/echomirage.oldbutgold.p/ (Product Reference)
www.vulncheck.com/...-buffer-overflow-via-rules-action-field (VulnCheck Advisory: Echo Mirage 3.1 Stack Buffer Overflow via Rules Action Field)