CVE-2018-25432: Arm Whois 3.11 Buffer Overflow via ASLR Bypass
Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler hijacking.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25432?
CVE-2018-25432 has a severity rating of high, with a score of 8.4.
How does CVE-2018-25432 allow code execution?
CVE-2018-25432 allows code execution by exploiting a buffer overflow to overwrite the structured exception handler.
What components are affected by CVE-2018-25432?
CVE-2018-25432 specifically affects Arm Whois version 3.11.
Are there any known exploits for CVE-2018-25432?
Yes, there are known exploits for CVE-2018-25432 that demonstrate the buffer overflow through a crafted input file.
What is a recommended mitigation for CVE-2018-25432?
To mitigate CVE-2018-25432, it is recommended to update to a patched version of Arm Whois or apply security measures to reduce exposure.