Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-42612

Опубликовано: 24 мая 2022
Источник: debian

Описание

A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
halibutfixed1.3-1package
halibutno-dsabullseyepackage
halibutno-dsabusterpackage

Примечания

  • https://carteryagemann.com/halibut-case-study.html#poc-halibut-text-uaf

  • Inventing an errorstate to pass to all err_* functions and use it to track fatal errors:

  • https://git.tartarus.org/?p=simon/halibut.git;a=commit;h=5c3db60a2911efb18bdc823264b74d8045c407b9 (1.3)

  • https://git.tartarus.org/?p=simon/halibut.git;a=commit;h=edaf724febe2f9c890ef1cfdf24a78d5c1da2b32 (1.3)

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document.

CVSS3: 7.8
nvd
больше 3 лет назад

A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document.

CVSS3: 7.8
github
больше 3 лет назад

A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document.