LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2018-25427

Published
CVSS9.8
Severitycritical
WeaknessCWE-121
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field. Attackers can craft malicious input exceeding 658 bytes with shellcode to overwrite the structured exception handler and gain command execution when the application processes the input.

References

← Back to the CVE Tracker

Our coverage of CVE-2018-25427

No stories yet. This page updates automatically when we publish reporting that references CVE-2018-25427.