CVE-2011-4620
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 13%
from disclosure to weapon0 days
Published on NVDDec 31
1st PoCDec 20
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message, as demonstrated by a crafted acc file for TORCS. NOTE: some of these details are obtained from third party information.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/18258/unverifiedexploitdbwww.exploit-db.com/exploits/18258unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00015.htmlhttp://openwall.com/lists/oss-security/2011/12/21/2http://osvdb.org/77973http://secunia.com/advisories/47297http://secunia.com/advisories/51340https://security.gentoo.org/glsa/201606-16http://www.exploit-db.com/exploits/18258/