Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-4025

Опубликовано: 19 июл. 2012
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:squashfs_project:squashfs:*:*:*:*:*:*:*:*
Версия до 4.2 (включая)

EPSS

Процентиль: 85%
0.02345
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-190

Связанные уязвимости

ubuntu
больше 13 лет назад

Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

redhat
больше 13 лет назад

Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

debian
больше 13 лет назад

Integer overflow in the queue_init function in unsquashfs.c in unsquas ...

github
больше 3 лет назад

Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

EPSS

Процентиль: 85%
0.02345
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-190