Description
Frigate 3.36.0.9 contains a local buffer overflow vulnerability in the Command Line input field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload to overflow the buffer, bypass DEP, and execute commands like launching calc.exe through a specially crafted input sequence.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Paras Bhatia
References
www.exploit-db.com/exploits/48563 (ExploitDB-48563)
web.archive.org/...3044943/http://www.frigate3.com/index.php (Archived Vendor Homepage)
www.vulncheck.com/...gate-command-line-local-buffer-overflow (VulnCheck Advisory: Frigate 3.36.0.9 - 'Command Line' Local Buffer Overflow)