Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-19847

Опубликовано: 17 дек. 2019
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.

An off-by-one vulnerability was found in libspiro in the way a double array is first declared in a unit test and then accessed by the library itself. Applications that make use of libspiro in the same way as the example code in the test suite may be vulnerable to this flaw. A remote attacker could abuse this flaw to make the application crash or potentially execute arbitrary code.

Отчет

This issue did not affect the versions of libspiro as shipped with Red Hat Enterprise Linux 6, 7, and 8 as they did not include the vulnerable code. The vulnerable function was introduced in a newer version of the package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libspiroNot affected
Red Hat Enterprise Linux 7libspiroNot affected
Red Hat Enterprise Linux 8libspiroNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=1786740libspiro: stack-based off-by-one buffer overflow in spiro_to_bpath0() in spiro.c

EPSS

Процентиль: 64%
0.00479
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 6 лет назад

Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.

CVSS3: 8.1
nvd
около 6 лет назад

Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.

CVSS3: 8.1
msrc
около 4 лет назад

Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.

CVSS3: 8.1
debian
около 6 лет назад

Libspiro through 20190731 has a stack-based buffer overflow in the spi ...

github
больше 3 лет назад

Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.

EPSS

Процентиль: 64%
0.00479
Низкий

8.1 High

CVSS3