Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-23318

Опубликовано: 17 фев. 2022
Источник: debian
EPSS Низкий

Описание

A heap-buffer-overflow in pcf2bdf, versions >= 1.05 allows an attacker to trigger unsafe memory access via a specially crafted PCF font file. This out-of-bound read may lead to an application crash, information disclosure via program memory or other context-dependent impact.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pcf2bdffixed1.07-1package

Примечания

  • https://github.com/ganaware/pcf2bdf/issues/4

  • https://github.com/advisories/GHSA-mhwp-x94h-mg49

  • Fixed by: https://github.com/ganaware/pcf2bdf/commit/aaf16808e4bb8d96eeab5f684df6550912a9e694 (1.07)

  • Crash in CLI tool, no security impact

EPSS

Процентиль: 38%
0.00169
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 4 года назад

A heap-buffer-overflow in pcf2bdf, versions >= 1.05 allows an attacker to trigger unsafe memory access via a specially crafted PCF font file. This out-of-bound read may lead to an application crash, information disclosure via program memory or other context-dependent impact.

CVSS3: 7.1
nvd
почти 4 года назад

A heap-buffer-overflow in pcf2bdf, versions >= 1.05 allows an attacker to trigger unsafe memory access via a specially crafted PCF font file. This out-of-bound read may lead to an application crash, information disclosure via program memory or other context-dependent impact.

github
почти 4 года назад

A heap-buffer-overflow in pcf2bdf, versions >= 1.05 allows an attacker to trigger unsafe memory access via a specially crafted PCF font file. This out-of-bound read may lead to an application crash, information disclosure via program memory or other context-dependent impact.

EPSS

Процентиль: 38%
0.00169
Низкий