Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27c8-cpgv-r39p

Опубликовано: 11 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.

An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.

EPSS

Процентиль: 96%
0.23681
Средний

9.8 Critical

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.

EPSS

Процентиль: 96%
0.23681
Средний

9.8 Critical

CVSS3

Дефекты

CWE-120