Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message, as demonstrated by a crafted acc file for TORCS. NOTE: some of these details are obtained from third party information.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade plib | Jul 30, 2024 | Dec 31, 2011 |
| Freebsd | — | Upgrade torcsUpgrade plib | Dec 10, 2025 | Feb 19, 2012 |
| Gentoo Linux | — | Upgrade media-libs/plib. | Oct 30, 2017 | Dec 30, 2011 |
| Suse | — | Upgrade plib-develUpgrade plibUpgrade plib-debugsourceUpgrade plib-debuginfo | Feb 17, 2015 | Dec 30, 2011 |
| Ubuntu | — | Upgrade plib | Nov 19, 2024 | Dec 31, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub