CVE-2016-20044: Surf Pinfo

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

PInfo 0.6.9-5.1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -m parameter. Attackers can craft a malicious input string with 564 bytes of padding followed by a return address to overwrite the instruction pointer and execute shellcode with user privileges.

Affected products

  • Surf Pinfo: up to and including 0.6.9-5.1

Published 2026-03-28. Last modified 2026-10-07.