Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000097

Опубликовано: 21 фев. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can result in Could lead to code execution. This attack appear to be exploitable via Victim have to run unshar command on a specially crafted file..

A heap-based out-of-bounds read flaw was found in the way Sharutils parsed archive files. An attacker could potentially use this flaw to crash Unshar by tricking it into processing crafted archive files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sharutilsNot affected
Red Hat Enterprise Linux 6sharutilsNot affected
Red Hat Enterprise Linux 7sharutilsNot affected
Red Hat Enterprise Linux 8sharutilsNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1548018sharutils: heap-buffer-overflow in find_archive in unshar.c

EPSS

Процентиль: 86%
0.02856
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can result in Could lead to code execution. This attack appear to be exploitable via Victim have to run unshar command on a specially crafted file..

CVSS3: 7.8
nvd
больше 7 лет назад

Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can result in Could lead to code execution. This attack appear to be exploitable via Victim have to run unshar command on a specially crafted file..

CVSS3: 7.8
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.8
debian
больше 7 лет назад

Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer ...

CVSS3: 7.8
github
около 3 лет назад

Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can result in Could lead to code execution. This attack appear to be exploitable via Victim have to run unshar command on a specially crafted file..

EPSS

Процентиль: 86%
0.02856
Низкий

3.3 Low

CVSS3