Description
A vulnerability was determined in LemonOS up to nightly-2024-07-12 on LemonOS. Affected by this issue is the function HTTPGet of the file /Applications/Steal/main.cpp of the component HTTP Client. The manipulation of the argument chunkSize leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Davon betroffen ist die Funktion HTTPGet der Datei /Applications/Steal/main.cpp der Komponente HTTP Client. Durch das Manipulieren des Arguments chunkSize mit unbekannten Daten kann eine stack-based buffer overflow-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Timeline
2025-08-13: | Advisory disclosed |
2025-08-13: | VulDB entry created |
2025-08-13: | VulDB entry last update |
Credits
0xHamy (VulDB User)
References
vuldb.com/?id.320030 (VDB-320030 | LemonOS HTTP Client main.cpp HTTPGet stack-based overflow)
vuldb.com/?ctiid.320030 (VDB-320030 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.624974 (Submit #624974 | LemonOS Lemon OS nightly-2024-07-12 Buffer Overflow)
hkohi.ca/vulnerability/16
github.com/LemonOSProject/LemonOS/issues/60