CVE-2016-20043
EUVD-2016-1084128.03.2026, 12:16
NRSS RSS Reader 0.3.9-1 contains a stack buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -F parameter. Attackers can craft a malicious input with 256 bytes of padding followed by a controlled EIP value to overwrite the return address and achieve code execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nrss | nrss | 𝑥 ≤ 0.3.9-1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration