Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-49287

Опубликовано: 04 дек. 2023
Источник: debian
EPSS Низкий

Описание

TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
falcosecurity-libsfixed0.14.1-1package
falcosecurity-libsno-dsabookwormpackage
gemmifixed0.6.4+ds-1package
gemmino-dsabookwormpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2023/12/04/1

  • https://github.com/cxong/tinydir/security/advisories/GHSA-jf5r-wgf4-qhxf

  • https://github.com/cxong/tinydir/commit/8124807260735a837226fa151493536591f6715d (1.2.6)

  • https://github.com/hnsecurity/vulns/blob/main/HNS-2023-04-tinydir.txt

  • gemmi: https://github.com/project-gemmi/gemmi/issues/292

  • gemmi: https://github.com/project-gemmi/gemmi/commit/e142eff1fec1475b62b2ab5e88d3a50b4d7450b5 (v0.6.4)

  • lwip embeds a copy of tinydir, but it's unused, see bug #1059259

EPSS

Процентиль: 85%
0.02487
Низкий

Связанные уязвимости

CVSS3: 7.7
ubuntu
около 2 лет назад

TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.

CVSS3: 7.7
nvd
около 2 лет назад

TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.

CVSS3: 9.8
fstec
около 2 лет назад

Уязвимость функции tinydir_file_open() программного средства чтения файлов TinyDir, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 85%
0.02487
Низкий