CVE-2019-25666
MEDIUMSpotAuditor 3.6.7 Denial of Service Buffer Overflow
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25666. PoCs published by Rafael Pedrero.
AI-analyzed exploit summary This Python script generates a buffer overflow payload to trigger a Denial of Service (DoS) in SpotAuditor v3.6.7 by exploiting a local buffer overflow vulnerability in the Base64 Password Decoder tool. The exploit creates a file with 2000 'A' characters, which when pasted into the tool and decrypted, causes the application to crash.
Description
SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition.
Exploits (1)
This Python script generates a buffer overflow payload to trigger a Denial of Service (DoS) in SpotAuditor v3.6.7 by exploiting a local buffer overflow vulnerability in the Base64 Password Decoder tool. The exploit creates a file with 2000 'A' characters, which when pasted into the tool and decrypted, causes the application to crash.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H