Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17533

Опубликовано: 13 окт. 2019
Источник: debian

Описание

Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libmatiofixed1.5.17-4package
libmationo-dsabusterpackage
libmationo-dsastretchpackage

Примечания

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16856

  • https://github.com/tbeu/matio/commit/651a8e28099edb5fbb9e4e1d4d3238848f446c9a

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 6 лет назад

Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.

CVSS3: 8.2
nvd
больше 6 лет назад

Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.

CVSS3: 8.2
github
больше 3 лет назад

Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.