CVE-2012-1189
TORCS < 1.3.3 and Speed Dreams - Stack-based Buffer Overflow via Long File Name in XML Configuration
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1189. PoCs published by Andres Gomez & David Mora.
AI-analyzed exploit summary This exploit leverages a buffer overflow vulnerability in TORCS <= 1.3.2 to achieve remote code execution by crafting a malicious XML file that triggers a SEH bypass and executes shellcode.
Description
Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an engine sample attribute in an xml configuration file.
Exploits (1)
This exploit leverages a buffer overflow vulnerability in TORCS <= 1.3.2 to achieve remote code execution by crafting a malicious XML file that triggers a SEH bypass and executes shellcode.