HomeSecurity5 buffer overflow vulnerabilities found in popular applications

5 buffer overflow vulnerabilities found in popular applications

buffer overflow

What is buffer overflow?

Buffer overflow is a softwarethat results in the program trying to store more data in the buffer than the default capacity, thus causing an overflow.

A buffer in a computer is a portion of memory that is allocated for storing data. If a data, this can lead to data corruption and the system itself, or lead to the execution of some malicious code.

NVIDIA SHIELD TV

NVIDIA SHIELD TV is vulnerable to attacks due to two vulnerabilities, on devices with software versions older than 8.0.1. The bug that causes a buffer overflow is identified as CVE – 2019-5699. NVIDIAhas released an update to fix the bug.

macOS Catalina

macOS Catalina 10.15 includes fixes for a number of vulnerabilities, including a buffer overflow bug, known as CVE-2019-8745, which was discovered in the UIFoundation component. UIFoundation is part of UIKit, a graphical interface framework that provides the necessary framework for iOS or tvOS applications. This means that it is a core part of the operating system. A bug in it poses the worst risks for macOS.

VPN products

The National Security Agency (NSA) recently warned administrators about current vulnerabilities being exploited by attackers – primarily state-sponsored hacker. The flaws are present in three popular VPN, Pulse Secure, Palo Alto GlobalProtect, and Fortinet Fortigate.

WhatsApp

Despite its end-to-end encryption WhatsAppalso has some vulnerabilities. A critical bug discovered in May in WhatsApp VoIP allowed an attacker to take control of a mobile device. The vulnerability was reported as a buffer overflow bug. In fact, the security flaw could help an attacker gain full access to a device, including camera and microphone sensors and file storage.

Exim

Exim, a mail transfer agent (MTA) developed at the University of Cambridge and powering more than half of the world's mail servers, was discovered in September with a buffer overflow vulnerability, known as CVE-2019-16928. This is a critical vulnerability that could allow denial of service (DoS) and remote code execution (RCE) attacks.

In conclusion

Because every software we use can present vulnerabilities, we need to see how we can protect our devices from a buffer overflow.

First, we update our systems regularly, as it is the only way to fix vulnerabilities in the software installed on our system. Next, for those who own a business, they should include antivirus and endpoint along with a firewall, as well as a network security program.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS