CVE-2016-20050: NetSchedScan 1.0 Buffer Overflow Denial of Service
NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a crafted payload containing 388 bytes of data followed by 4 bytes of EIP overwrite into the Hostname/IP field to trigger a denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-20050?
CVE-2016-20050 has a severity rating of medium due to its potential to cause denial of service.
How do I fix CVE-2016-20050?
To mitigate CVE-2016-20050, users should avoid providing oversized input strings and update to a patched version if available.
Who is affected by CVE-2016-20050?
CVE-2016-20050 specifically affects users of NetSchedScan version 1.0.
What type of vulnerability is CVE-2016-20050?
CVE-2016-20050 is classified as a buffer overflow vulnerability leading to denial of service.
Can CVE-2016-20050 be exploited remotely?
CVE-2016-20050 cannot be exploited remotely as it requires local access to the application.