Unrated severityNVD Advisory· Published Mar 28, 2026· Updated Mar 30, 2026
EKG Gadu 1.9 Local Buffer Overflow via Username Parameter
CVE-2016-20047
Description
EKG Gadu 1.9~pre+r2855-3+b1 contains a local buffer overflow vulnerability in the username handling that allows local attackers to execute arbitrary code by supplying an oversized username string. Attackers can trigger the overflow in the strlcpy function by passing a crafted buffer exceeding 258 bytes to overwrite the instruction pointer and execute shellcode with user privileges.
Affected products
2- ekg/EKG Gaduv5Range: 1:1.9~pre+r2855-3+b1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/40392mitreexploit
- www.vulncheck.com/advisories/ekg-gadu-local-buffer-overflow-via-username-parametermitrethird-party-advisory
- ekg.chmurka.netmitreproduct
News mentions
0No linked articles in our index yet.