Zoom Client for Linux CVE-2017-15048 Stack-Based Buffer Overflow Vulnerability
BID:102261
Info
Zoom Client for Linux CVE-2017-15048 Stack-Based Buffer Overflow Vulnerability
| Bugtraq ID: | 102261 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-15048 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2017 12:00AM |
| Updated: | Dec 19 2017 12:00AM |
| Credit: | Gabriel Quadros |
| Vulnerable: |
Zoom Client for Linux 2.0.106600.0904 |
| Not Vulnerable: |
Zoom Client for Linux 2.0.115900.1201 |
Discussion
Zoom Client for Linux CVE-2017-15048 Stack-Based Buffer Overflow Vulnerability
Zoom Client for Linux is prone to a stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Successful exploits may allow an attacker to execute arbitrary code in context of an affected application. Failed attempts will likely cause a denial-of-service condition.
Versions prior to Zoom Client for Linux 2.0.115900.1201 are vulnerable.
Zoom Client for Linux is prone to a stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Successful exploits may allow an attacker to execute arbitrary code in context of an affected application. Failed attempts will likely cause a denial-of-service condition.
Versions prior to Zoom Client for Linux 2.0.115900.1201 are vulnerable.
Exploit / POC
Zoom Client for Linux CVE-2017-15048 Stack-Based Buffer Overflow Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Zoom Client for Linux CVE-2017-15048 Stack-Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Zoom Client for Linux CVE-2017-15048 Stack-Based Buffer Overflow Vulnerability
References:
References:
- [CONVISO-17-002] - Zoom Linux Client Stack-based Buffer Overflow Vulnerability (Seclists.org)
- New Updates for Linux Follow (Zoom)
- Zoom Homepage (Zoom)