CVE-2011-4620

PLIB 1.8.5 - Buffer Overflow in ulSetError Function

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4620. PoCs published by Andrés Gómez.

AI-analyzed exploit summary This exploit generates a malformed ACC file for TORCS 1.3.1, triggering a buffer overflow via a crafted MATERIAL field containing NOP sleds and shellcode. The shellcode binds a TCP shell on port 4444, achieving remote code execution when the file is loaded.

Description

Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message, as demonstrated by a crafted acc file for TORCS. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Andrés Gómez · clocalwindows
https://www.exploit-db.com/exploits/18258

This exploit generates a malformed ACC file for TORCS 1.3.1, triggering a buffer overflow via a crafted MATERIAL field containing NOP sleds and shellcode. The shellcode binds a TCP shell on port 4444, achieving remote code execution when the file is loaded.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: TORCS 1.3.1
No auth needed
Prerequisites: Ability to place a malicious ACC file in TORCS' data directory · Victim must load the malicious file in TORCS
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51340
Third Party Advisory, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47297
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18258/
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201606-16
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/77973
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00013.html
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2011/12/21/2
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00015.html

Scores

EPSS 0.1280
EPSS Percentile 95.8%

Details

CWE
CWE-119
Status published
Products (1)
steve_j_baker/plib 1.8.5
Published Dec 31, 2011
Tracked Since Feb 18, 2026