CVE-2016-20047

HIGH

EKG Gadu 1.9 Local Buffer Overflow via Username Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20047. PoCs published by Juan Sacco.

AI-analyzed exploit summary This exploit demonstrates a local buffer overflow in EKG Gadu by overflowing the USERNAME field with a NOP sled, shellcode, and a controlled EIP to achieve arbitrary code execution. The shellcode spawns a shell, and the exploit is tested on Kali Linux 2.0.

Description

EKG Gadu 1.9~pre+r2855-3+b1 contains a local buffer overflow vulnerability in the username handling that allows local attackers to execute arbitrary code by supplying an oversized username string. Attackers can trigger the overflow in the strlcpy function by passing a crafted buffer exceeding 258 bytes to overwrite the instruction pointer and execute shellcode with user privileges.

Exploits (1)

exploitdb WORKING POC
by Juan Sacco · pythonlocallinux
https://www.exploit-db.com/exploits/40392

This exploit demonstrates a local buffer overflow in EKG Gadu by overflowing the USERNAME field with a NOP sled, shellcode, and a controlled EIP to achieve arbitrary code execution. The shellcode spawns a shell, and the exploit is tested on Kali Linux 2.0.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EKG Gadu 1:1.9~pre+r2855-3+b1
No auth needed
Prerequisites: EKG Gadu installed locally · Python environment
devstral-2 · analyzed Apr 08, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-40392
https://www.exploit-db.com/exploits/40392
Product product
Official Product Homepage
http://ekg.chmurka.net/
Third Party Advisory third-party-advisory
VulnCheck Advisory: EKG Gadu 1.9 Local Buffer Overflow via Username Parameter
https://www.vulncheck.com/advisories/ekg-gadu-local-buffer-overflow-via-username-parameter

Scores

CVSS v3 8.4
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (1)
ekg/EKG Gadu 1:1.9~pre+r2855-3+b1
Published Mar 28, 2026
Tracked Since Mar 29, 2026