ZOC Terminal Buffer Overflow Vulnerability Leading to Denial-of-Service

Vulnerability

A buffer overflow vulnerability has been identified in ZOC Terminal version 7.23.4. The issue resides in the Shell field of the Program Settings, where local attackers can crash the application by entering an excessively long string. This vulnerability can be exploited by pasting a crafted payload into the Shell configuration field, which then triggers a crash when the Command Shell feature is accessed.

Impact

Exploitation of this vulnerability causes the application to crash, leading to a denial-of-service condition.

Reproduction

To reproduce this vulnerability, first create a text file containing a long string of approximately 270 characters, consisting of repeated 'A' characters. After saving the file, open ZOC Terminal and navigate to the Program Settings under the Options menu. In the Special Files section, locate the 'Shell' field, clear its contents, and paste the clipboard data from the text file. Save the changes, then access the Command Shell feature, which will result in the application crashing.

Added: Mar 22, 2026, 1:24 AM
Updated: Mar 22, 2026, 1:24 AM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
2.5
exploitability
4.6
remediation
0.0
relevance
4.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.