漏洞描述
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
hyp3rlinx.altervista.orghttp://hyp3rlinx.altervista.org/advisories/CLOUDME-SYNC-UNAUTHENTICATED-REMOTE-BUFFER-OVERFLOW.txt↗packetstormsecurity.comhttp://packetstormsecurity.com/files/157407/CloudMe-1.11.2-Buffer-Overflow.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/158716/CloudMe-1.11.2-SEH-Buffer-Overflow.html↗blogs.securiteam.comhttps://blogs.securiteam.com/index.php/archives/3669↗packetstormsecurity.comhttp://packetstormsecurity.com/files/159327/CloudMe-1.11.2-Buffer-Overflow.html↗