Description
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the 'Find Computer' feature that allows attackers to execute arbitrary code by overflowing the computer name input field. Attackers can craft a malicious payload that triggers a buffer overflow, enabling code execution and launching calculator as a proof of concept.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Paras Bhatia
References
www.exploit-db.com/exploits/48579 (ExploitDB-48579)
web.archive.org/...3044943/http://www.frigate3.com/index.php (Archived Vendor Homepage)
www.vulncheck.com/...nal-find-computer-local-buffer-overflow (VulnCheck Advisory: Frigate Professional 3.36.0.9 - 'Find Computer' Local Buffer Overflow)