PInfo Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A local buffer overflow vulnerability has been identified in PInfo version 0.6.9-5.1. This vulnerability allows local attackers to execute arbitrary code by providing an oversized argument to the '-m' parameter. The exploitation involves crafting a malicious input string with 564 bytes of padding followed by a return address, which overwrites the instruction pointer and enables the execution of shellcode with user privileges.

Impact

Exploitation of this vulnerability leads to a local buffer overflow, allowing for arbitrary code execution with user privileges.

Reproduction

The vulnerability can be reproduced by using PInfo version 0.6.9-5.1 on a Linux platform. The exploit involves sending a crafted input to the '-m' parameter, which includes 564 bytes of padding followed by a return address. This input overwrites the instruction pointer, causing a segmentation fault and allowing for the execution of injected shellcode.

Added: Mar 28, 2026, 12:21 PM
Updated: Mar 28, 2026, 12:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.0
remediation
0.0
relevance
4.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.