Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cgrj-mh7v-v4c8

Опубликовано: 23 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

EPSS

Процентиль: 1%
0.00107
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-134

Связанные уязвимости

CVSS3: 6.8
ubuntu
10 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

CVSS3: 6.8
redhat
11 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

CVSS3: 6.8
nvd
10 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

msrc
8 дней назад

Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.

CVSS3: 6.8
debian
10 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. Wh ...

EPSS

Процентиль: 1%
0.00107
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-134