Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-247v-6wr5-3wf3

Опубликовано: 26 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

EPSS

Процентиль: 10%
0.00037
Низкий

7 High

CVSS3

Дефекты

CWE-121
CWE-787

Связанные уязвимости

CVSS3: 6.7
ubuntu
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
redhat
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
nvd
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
msrc
4 месяца назад

Описание отсутствует

CVSS3: 6.7
debian
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC ...

EPSS

Процентиль: 10%
0.00037
Низкий

7 High

CVSS3

Дефекты

CWE-121
CWE-787