NetSchedScan Buffer Overflow Vulnerability Leading to Denial-of-Service
Vulnerability
A buffer overflow vulnerability has been identified in NetSchedScan version 1.0. This vulnerability resides in the scan Hostname/IP field, where local attackers can cause the application to crash by inputting an excessively long string. By pasting a crafted payload of 388 bytes followed by 4 bytes to overwrite the EIP, attackers can trigger a denial-of-service condition.
Impact
Exploitation of this vulnerability causes the application to crash, creating a denial-of-service condition.
Reproduction
The vulnerability can be reproduced by overwriting the EIP with a crafted payload. This can be done by using a Python script to generate the payload, which consists of 388 bytes of buffer followed by 4 bytes to overwrite the EIP. After copying this payload into the clipboard, it can be pasted into the Hostname/IP field of the NetSchedScan application, which will then crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
