Описание
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour).
Ссылки
- ExploitIssue TrackingPatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- ExploitIssue TrackingPatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.6.6 (включая) до 9.2.0 (включая)
Одновременно
cpe:2.3:a:zope:grok:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
EPSS
Процентиль: 61%
0.00409
Низкий
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-787
Связанные уязвимости
CVSS3: 7.8
ubuntu
больше 4 лет назад
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour).
CVSS3: 7.8
debian
больше 4 лет назад
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::File ...
github
больше 3 лет назад
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour).
EPSS
Процентиль: 61%
0.00409
Низкий
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-787