Vulnerabilities > CVE-2019-17601 - Out-of-bounds Write vulnerability in Minishare Project Minishare 1.4.1

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
minishare-project
CWE-787
critical

Summary

In MiniShare 1.4.1, there is a stack-based buffer overflow via an HTTP CONNECT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19862 and CVE-2018-19861. NOTE: this product is discontinued.

Vulnerable Configurations

Part Description Count
Application
Minishare_Project
1

Common Weakness Enumeration (CWE)