packetstormsecurity.com
http://packetstormsecurity.com/files/145452/Zoom-Linux-Client-2.0.106600.0904-Buffer-Overflow.html CVE-2017-15048
HIGH
Zoom Linux Client 2.0.106600.0904 - Stack-Based Buffer Overflow (PoC)
Record summary
CVE-2017-15048 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBZoom Linux Client 2.0.106600.0904 - Stack-Based Buffer Overflow (PoC)ExploitDB exploitby ConvisoNot analyzed1 file
References
520171215 [CONVISO-17-002] - Zoom Linux Client Stack-based Buffer Overflow Vulnerabilitymailing list
http://seclists.org/fulldisclosure/2017/Dec/46 github.com
https://github.com/convisoappsec/advisories/blob/master/2017/CONVISO-17-002.txt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-15048 43355exploit
https://www.exploit-db.com/exploits/43355