Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-4025

Опубликовано: 19 июл. 2012
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:squashfs_project:squashfs:*:*:*:*:*:*:*:*
Версия до 4.2 (включая)

EPSS

Процентиль: 89%
0.03898
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-190

Связанные уязвимости

ubuntu
около 14 лет назад

Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

redhat
около 14 лет назад

Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

debian
около 14 лет назад

Integer overflow in the queue_init function in unsquashfs.c in unsquas ...

github
около 4 лет назад

Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

EPSS

Процентиль: 89%
0.03898
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-190