freecode.comConfirmation
http://freecode.com/projects/torcs/releases/341672 CVE-2012-1189
TORCS 1.3.2 - '.xml' File Buffer Overflow /SafeSEH Evasion
Record summary
CVE-2012-1189 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an engine sample attribute in an xml configuration file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTORCS 1.3.2 - '.xml' File Buffer Overflow /SafeSEH EvasionExploitDB exploitby Andres Gomez & David MoraNot analyzed1 file
References
7torcs.sourceforge.netConfirmation
http://torcs.sourceforge.net/index.php?name=News&file=article&sid=79 18471exploit
http://www.exploit-db.com/exploits/18471 [oss-security] 20120218 TORCS 1.3.2 xml buffer overflow - CVE-2012-1189mailing list
http://www.openwall.com/lists/oss-security/2012/02/18/2 [oss-security] 20120305 Re: TORCS 1.3.2 xml buffer overflow - CVE-2012-1189mailing list
http://www.openwall.com/lists/oss-security/2012/03/05/18 79372vdb entry
http://www.osvdb.org/79372 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-1189