Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mh8-m4xv-8wfr

Опубликовано: 05 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.

In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.

EPSS

Процентиль: 91%
0.06148
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 лет назад

In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.

EPSS

Процентиль: 91%
0.06148
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119