Faleemi Plus Buffer Overflow Vulnerability Leading to Denial-of-Service
Vulnerability
A buffer overflow vulnerability has been identified in Faleemi Plus version 1.0.2. This vulnerability allows local attackers to crash the application by sending oversized input strings. During the process of adding a camera, attackers can paste a 2000-byte payload into the Camera name and DID number fields, which triggers the application to crash.
Impact
Exploitation of this vulnerability causes the application to crash, leading to a denial-of-service condition.
Reproduction
To reproduce this vulnerability, first create a 2000-byte payload consisting of repeated characters. Save this payload to a text file. Then, open Faleemi Plus version 1.0.2 and navigate to the 'Add Camera' feature. In the 'Camera name' and 'DID number' fields, paste the content of the text file containing the payload. Click 'Add' to trigger the application crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
