Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12096

Опубликовано: 19 июн. 2018
Источник: debian
EPSS Низкий

Описание

The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub

Пакеты

ПакетСтатусВерсия исправленияРелизТип
liblnkfixed20180626-1package

Примечания

  • http://seclists.org/fulldisclosure/2018/Jun/33

  • https://github.com/libyal/liblnk/issues/32

  • https://github.com/libyal/liblnk/issues/33

  • https://github.com/libyal/libuna/commit/aca678aa7e49ca628f1b27a53fdea883fa8764bb

  • https://github.com/libyal/libuna/commit/f22aca8b649afe5cef529d9268186bfe591b7f89

  • Questionable/negligabe security impact

EPSS

Процентиль: 28%
0.00099
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub

CVSS3: 5.5
nvd
больше 7 лет назад

The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub

CVSS3: 5.5
github
больше 3 лет назад

** DISPUTED ** The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub.

EPSS

Процентиль: 28%
0.00099
Низкий