CVE-2024-25003
KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
6Exploited in Wild
-Decision
Descriptions
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization. This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.
Las versiones de KiTTY 0.76.1.13 y anteriores son vulnerables a un desbordamiento de búfer en la región stack de la memoria a través del nombre de host, que se produce debido a una verificación de los límites y una sanitización de entrada insuficientes. Esto permite a un atacante sobrescribir la memoria adyacente, lo que conduce a la ejecución de código arbitrario.
KiTTY versions 0.76.1.13 and below suffer from a command injection vulnerability when getting a remote file through scp. It appears to leverage an ANSI escape sequence issue which is quite an interesting vector of attack.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-02-02 CVE Reserved
- 2024-02-08 CVE Published
- 2024-02-08 First Exploit
- 2024-08-01 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (8)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/177031 | 2024-02-08 | |
https://packetstorm.news/files/id/177032 | 2024-02-08 | |
https://www.exploit-db.com/exploits/51890 | 2024-03-14 | |
http://seclists.org/fulldisclosure/2024/Feb/13 | 2024-08-01 | |
http://seclists.org/fulldisclosure/2024/Feb/14 | 2024-08-01 | |
https://blog.defcesco.io/CVE-2024-25003-CVE-2024-25004 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
9bis Search vendor "9bis" | Kitty Search vendor "9bis" for product "Kitty" | <= 0.76.1.13 Search vendor "9bis" for product "Kitty" and version " <= 0.76.1.13" | windows |
Affected
|