CVE-2018-8072

Problém byl objeven na EDIMAX IC-3140W přes 3.06, IC-5150W přes 3.09 a IC-6220DC prostřednictvím 3,06 zařízení. The ipcam_cgi binary contains a stack-based buffer overflow that is possible to trigger from a remote unauthenticated /camera-cgi/public/getsysyeminfo.cgi?action=VALUE_HERE HTTP request: if the VALUE_HERE length is more than 0x400 (1024), it is possible to overwrite other values ​​located on the stack due to an incorrect use of the strcpy() funkce.

CONFIRM: https://www.edimax.com/edimax/download/download/data/edimax/uk/download/for_home/home_network_cameras/home_network_cameras_indoor_fixed/ic-3140w
MISC: https://gitlab.com/nemux/CVE-2018-8072/blob/master/CVE-2018-8072_PoC.txt
MISC: https://gitlab.com/nemux/CVE-2018-8072/blob/master/nemux_codemotion_Rome18_cover.pdf
MISC: https://www.nemux.org/2018/04/24/cve-2018-8072/
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8072

14 let
257 zemí
685k uživatelů
4536k výpočtů
Logo secutek.cz
Logo ipcamtalk.com
Logo www.use-ip.co.uk
Logo zoneway.cz
Logo sectech.co.nz
Logo ru.kedacom.com