Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6rfm-3v66-6wr2

Опубликовано: 22 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

EPSS

Процентиль: 5%
0.00023
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

CVSS3: 5.5
redhat
почти 3 года назад

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

CVSS3: 5.5
nvd
почти 3 года назад

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

CVSS3: 5.5
msrc
почти 3 года назад

In pkgconf through 1.9.3 variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example a .pc file containing a few hundred bytes can expand to one billion bytes.

CVSS3: 5.5
debian
почти 3 года назад

In pkgconf through 1.9.3, variable duplication can cause unbounded str ...

EPSS

Процентиль: 5%
0.00023
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787