CVE-2018-25253
MEDIUMTermite 3.4 Denial of Service via Settings Buffer Overflow
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25253. PoCs published by Abdullah Alıç.
AI-analyzed exploit summary This Python script generates a large buffer of 'A' characters (2000 bytes) and writes it to a file named 'boom.txt'. The payload is designed to trigger a denial of service (DoS) in Termite 3.4 when pasted into the 'User interface language' field in the application's settings.
Description
Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local attackers to cause a denial of service by supplying an excessively long string. Attackers can paste a 2000-byte payload into the Settings User interface language field to crash the application.
Exploits (1)
This Python script generates a large buffer of 'A' characters (2000 bytes) and writes it to a file named 'boom.txt'. The payload is designed to trigger a denial of service (DoS) in Termite 3.4 when pasted into the 'User interface language' field in the application's settings.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H