Executive brief
MOOS ui-moos is a graphical user interface toolkit for the MOOS (Mission Oriented Operating System) project. The vulnerability allows attackers to crash the application or execute arbitrary code by providing excessively long process or variable names when an operator interacts with the process list or variable controls, potentially compromising systems that use this tool for autonomous vehicle or marine robotics monitoring.
Technical details
A stack-based buffer overflow exists in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf() without bounds checking. When an operator selects a process list entry or pokes a variable, attacker-controlled MOOS identifiers (client names or variable names) are formatted into these buffers without validation, causing a stack overflow. The vulnerability is triggered through operator interaction with the UI (e.g., selecting items from a process list). Successful exploitation enables arbitrary code execution with the privileges of the user running ui-moos. No patch status is currently indicated.
Affected products
- MOOS Project ui-moos through commit 50b9c6c
Timeline
- 2026-09-03: disclosed