CVE-2024-25003: Buffer Overflow
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization. This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25003?
CVE-2024-25003 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-25003?
To resolve CVE-2024-25003, upgrade KiTTY to version 0.76.1.14 or later, which includes the necessary security patches.
What causes the vulnerability CVE-2024-25003?
CVE-2024-25003 is caused by a stack-based buffer overflow resulting from insufficient bounds checking and input sanitization.
Who is affected by CVE-2024-25003?
Any user running KiTTY version 0.76.1.13 or earlier on Windows is potentially affected by CVE-2024-25003.
What type of vulnerability is CVE-2024-25003?
CVE-2024-25003 is a stack-based buffer overflow vulnerability that allows remote code execution.