Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-47436

Опубликовано: 14 мая 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Heap-based Buffer Overflow vulnerability in Apache ORC.

A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it. It causes memory corruption.

This issue affects Apache ORC C++ library: through 1.8.8, from 1.9.0 through 1.9.5, from 2.0.0 through 2.0.4, from 2.1.0 through 2.1.1.

Users are recommended to upgrade to version 1.8.9, 1.9.6, 2.0.5, and 2.1.2, which fix the issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:*
Версия до 1.8.9 (исключая)
cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:*
Версия от 1.9.0 (включая) до 1.9.6 (исключая)
cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.0.5 (исключая)
cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:*
Версия от 2.1.0 (включая) до 2.1.2 (исключая)

EPSS

Процентиль: 22%
0.00073
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 9.8
github
9 месяцев назад

Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it. It causes memory corruption. This issue affects Apache ORC C++ library: through 1.8.8, from 1.9.0 through 1.9.5, from 2.0.0 through 2.0.4, from 2.1.0 through 2.1.1. Users are recommended to upgrade to version 1.8.9, 1.9.6, 2.0.5, and 2.1.2, which fix the issue.

EPSS

Процентиль: 22%
0.00073
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-122