Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-24240

Опубликовано: 25 авг. 2020
Источник: nvd
CVSS3: 5.5
CVSS2: 7.1
EPSS Низкий

Описание

GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:bison:3.7:*:*:*:*:*:*:*

EPSS

Процентиль: 60%
0.00403
Низкий

5.5 Medium

CVSS3

7.1 High

CVSS2

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.

CVSS3: 5.5
redhat
больше 5 лет назад

GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.

CVSS3: 5.5
debian
больше 5 лет назад

GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/ob ...

github
больше 3 лет назад

GNU Bison 3.7 has a use after free (UAF) vulnerability. A local attacker may execute bison with crafted input file containing a NULL byte, which could triggers UAF and thus cause system crash.

EPSS

Процентиль: 60%
0.00403
Низкий

5.5 Medium

CVSS3

7.1 High

CVSS2

Дефекты

CWE-416