VulnerabilityModified
CVE-2010-1688
Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) .sps or (2) zip profile.
HIGH 9.3EPSS 15.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) .sps or (2) zip profile.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 15.01% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- 2brightsparks/syncback
- Source
- cve@mitre.org
References
- http://osvdb.org/64752
- http://secunia.com/advisories/39865Vendor Advisory
- http://www.2brightsparks.com/freeware/changes.htmlPatch
- http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-041-syncback-freeware-v3-2-20-0/Exploit
- http://www.corelan.be:8800/wp-content/forum-file-uploads/lincoln/syncbackup.rb_.txt
- http://www.securityfocus.com/bid/40311Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58727
- http://osvdb.org/64752
- http://secunia.com/advisories/39865Vendor Advisory
- http://www.2brightsparks.com/freeware/changes.htmlPatch
- http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-041-syncback-freeware-v3-2-20-0/Exploit
- http://www.corelan.be:8800/wp-content/forum-file-uploads/lincoln/syncbackup.rb_.txt
- http://www.securityfocus.com/bid/40311Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58727
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.