nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects text file.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.mogozobo.com/?p=3534 | exploit vendor advisory |
http://packetstormsecurity.com/files/153612/SNMPc-Enterprise-Edition-9-10-Mapping-Filename-Buffer-Overflow.html | exploit vdb entry third party advisory |