UML_NET Integer Mismanagement Code...

- AV AC AU C I A
发布: 2003-05-24
修订: 2025-04-13

A vulnerability has been discovered in uml_net. Due to integer mismanagement while handling version information, it may be possible for an attacker to execute arbitrary code. Specifically, by supplying a negative value within the version information it is possible to bypass various calculations and cause an invalid indexing into an array of functions. As a result, it is possible for an attacker to execute a function in an attacker-controlled location of memory. Successful exploitation of this vulnerability would allow an attacker to execute arbitrary commands with the privileges of uml_net, possibly root.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息