Description
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.
Problem types
Product status
Credits
MasterVlad
References
www.exploit-db.com/exploits/48688 (ExploitDB-48688)
web.archive.org/...6000613/http://www.frigate3.com/index.php (Archived Vendor Homepage)
www.vulncheck.com/...pack-file-buffer-overflow-seh-egghunter (VulnCheck Advisory: Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter))