A stack-based buffer overflow exists in Achat v0.150 in...
Critical severity
Unreviewed
Published
Jul 17, 2025
to the GitHub Advisory Database
•
Updated Jul 17, 2025
Description
Published by the National Vulnerability Database
Jul 16, 2025
Published to the GitHub Advisory Database
Jul 17, 2025
Last updated
Jul 17, 2025
A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted message to the UDP port 9256, an attacker can overwrite the structured exception handler (SEH) due to insufficient bounds checking on user-supplied input leading to remote code execution.
References