Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrm3-57g8-gwv8

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.

Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.

EPSS

Процентиль: 90%
0.05512
Низкий

7.3 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 19 лет назад

Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.

CVSS3: 7.3
nvd
больше 19 лет назад

Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.

CVSS3: 7.3
debian
больше 19 лет назад

Buffer overflow in getsym in tekhex.c in libbfd in Free Software Found ...

EPSS

Процентиль: 90%
0.05512
Низкий

7.3 High

CVSS3

Дефекты

CWE-787