A stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5.3. nmea_parse() in parser.c allows an attacker to trigger denial of service (even arbitrary code execution in a certain context) in a product using this library via malformed data.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.cnblogs.com/tr3e/p/9662324.html | third party advisory exploit |