CVE-2018-25216
MEDIUMAnyBurn 4.3 Denial of Service Local Buffer Overflow
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25216. PoCs published by Achilles.
AI-analyzed exploit summary This exploit demonstrates a local buffer overflow vulnerability in AnyBurn 4.3 (32-bit) by generating a malicious payload file (Evil.txt) that triggers a crash when pasted into the 'Image file name' field during disk-to-image operations. The PoC uses a simple Python script to create a 10,000-byte buffer of 'A' characters, which overwrites memory and causes a denial of service.
Description
AnyBurn 4.3 contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the image file name field. Attackers can paste a 10000-byte payload into the 'Image file name' parameter during the 'Copy disk to Image' operation to trigger a denial of service condition.
Exploits (1)
This exploit demonstrates a local buffer overflow vulnerability in AnyBurn 4.3 (32-bit) by generating a malicious payload file (Evil.txt) that triggers a crash when pasted into the 'Image file name' field during disk-to-image operations. The PoC uses a simple Python script to create a 10,000-byte buffer of 'A' characters, which overwrites memory and causes a denial of service.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H