Описание
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
Ссылки
- Third Party Advisory
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
- Patch
- Third Party Advisory
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
- Patch
Уязвимые конфигурации
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
Heap-based buffer overflow in the yy_get_next_buffer function in Flex ...
Security update for flex, at, libbonobo, netpbm, openslp, sgmltool, virtuoso
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2