Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://aluigi.org/poc/steamcazz.zip | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39928 | vdb entry |
http://aluigi.altervista.org/adv/steamcazz-adv.txt | exploit |