CVE-2016-20044

PInfo 0.6.9-5.1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -m parameter. Attackers can craft a malicious input string with 564 bytes of padding followed by a return address to overwrite the instruction pointer and execute shellcode with user privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:surf:pinfo:*:*:*:*:*:*:*:*

History

10 Apr 2026, 20:58

Type Values Removed Values Added
CPE cpe:2.3:a:surf:pinfo:*:*:*:*:*:*:*:*
First Time Surf
Surf pinfo
References () http://pinfo.alioth.debian.org/ - () http://pinfo.alioth.debian.org/ - Broken Link, Product
References () https://www.exploit-db.com/exploits/40023 - () https://www.exploit-db.com/exploits/40023 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/pinfo-local-buffer-overflow-via-m-parameter - () https://www.vulncheck.com/advisories/pinfo-local-buffer-overflow-via-m-parameter - Third Party Advisory
Summary
  • (es) PInfo 0.6.9-5.1 contiene una vulnerabilidad de desbordamiento de búfer local que permite a atacantes locales ejecutar código arbitrario al proporcionar un argumento sobredimensionado al parámetro -m. Los atacantes pueden crear una cadena de entrada maliciosa con 564 bytes de relleno seguida de una dirección de retorno para sobrescribir el puntero de instrucción y ejecutar shellcode con privilegios de usuario.

28 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-28 12:16

Updated : 2026-04-10 20:58


NVD link : CVE-2016-20044

Mitre link : CVE-2016-20044

CVE.ORG link : CVE-2016-20044


JSON object : View

Products Affected

surf

  • pinfo
CWE
CWE-787

Out-of-bounds Write