PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via return-oriented programming gadgets.
Metrics
Affected Vendors & Products
References
History
Mon, 30 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pms
Pms pms |
|
| Vendors & Products |
Pms
Pms pms |
Sat, 28 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via return-oriented programming gadgets. | |
| Title | PMS 0.42 Stack-Based Buffer Overflow via Configuration File | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-28T11:58:16.513Z
Updated: 2026-03-30T17:25:30.861Z
Reserved: 2026-03-28T11:49:40.863Z
Link: CVE-2018-25224
Updated: 2026-03-30T17:25:24.681Z
Status : Awaiting Analysis
Published: 2026-03-28T12:16:03.370
Modified: 2026-03-30T13:26:07.647
Link: CVE-2018-25224
No data.