HackDig : Dig high-quality web security articles for hacker

CVE-2014-5439 - Root shell on Sniffit [with exploit]

2014-11-26 23:15

CVE-2014-5439 - Root shell on Sniffit

Sniffit is a packet sniffer and monitoring tool.

The attacker can create a specially-crafted sniffit configuration file, which is able

to bypass all three protection mechanisms:

- Non-eXecutable bit NX
- Stack Smashing Protector SSP
- Address Space Layout Randomisation ASLR

And execute arbitrary code with root privileges.

Exploit, fix and discussion in:

http://hmarco.org/bugs/CVE-2014-5439-sniffit_0.3.7-stack-buffer-overflow.html


Regards,
Hector Marco.
http://hmarco.org

Cybersecurity researcher at:
http://cybersecurity.upv.es/



_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/


Source: 88/voN/4102/erusolcsidlluf/gro.stsilces

Read:2269 | Comments:0 | Tags: exploit

“CVE-2014-5439 - Root shell on Sniffit [with exploit]”0 Comments

Submit A Comment

Name:

Email:

Blog :

Verification Code:

Announce

Share high-quality web security related articles with you:)

Tools

Tag Cloud