EIP-2026-100690

PRE-CVE

BSD 4.2 - 'fingerd' Remote Buffer Overflow

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100690. PoCs published by anonymous.

AI-analyzed exploit summary This is a historical writeup describing a buffer overflow vulnerability in the fingerd service, which was exploited by the Internet Worm in 1988. The document explains the use of the gets() function leading to a stack-based overflow and provides the VAX machine code used to execute /bin/sh.

Description

BSD 4.2 - 'fingerd' Remote Buffer Overflow

Exploits (1)

exploitdb WRITEUP VERIFIED
by anonymous · textremotebsd
https://www.exploit-db.com/exploits/19039

This is a historical writeup describing a buffer overflow vulnerability in the fingerd service, which was exploited by the Internet Worm in 1988. The document explains the use of the gets() function leading to a stack-based overflow and provides the VAX machine code used to execute /bin/sh.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: fingerd (versions affected by the 1988 buffer overflow)
No auth needed
Prerequisites: Network access to a vulnerable fingerd service
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026