Impact
NASA Trick 19.6.0 contains a stack‑based buffer overflow in the JSONVariableServerThread::parse_request function. The overflow is triggered by an unbounded sscanf on received TCP data, allowing an attacker to corrupt the stack and potentially execute arbitrary code. This flaw can compromise confidentiality, integrity, and availability of the affected process when exploited.
Affected Systems
The vulnerability affects NASA Trick version 19.6.0. No other versions were listed as affected in the available data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, but the flaw is exploitable remotely over the network, and there is no EPSS score or KEV listing available. The lack of mitigation from the vendor and the remote attack surface suggest a tangible risk of exploitation if the vulnerable component is exposed to untrusted network traffic.
OpenCVE Enrichment