PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via return-oriented programming gadgets.
Metrics
Affected Vendors & Products
References
History
Sat, 28 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via return-oriented programming gadgets. | |
| Title | PMS 0.42 Stack-Based Buffer Overflow via Configuration File | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-28T11:58:16.513Z
Reserved: 2026-03-28T11:49:40.863Z
Link: CVE-2018-25224
No data.
Status : Received
Published: 2026-03-28T12:16:03.370
Modified: 2026-03-28T12:16:03.370
Link: CVE-2018-25224
No data.
OpenCVE Enrichment
No data.