Описание
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- Patch
- Mailing ListThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- Patch
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:matio_project:matio:1.5.17:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00547
Низкий
8.2 High
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-125
Связанные уязвимости
CVSS3: 8.2
ubuntu
больше 6 лет назад
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
CVSS3: 8.2
debian
больше 6 лет назад
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' ch ...
CVSS3: 8.2
github
больше 3 лет назад
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
EPSS
Процентиль: 67%
0.00547
Низкий
8.2 High
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-125