Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-35357

Опубликовано: 22 авг. 2023
Источник: redhat
CVSS3: 6.5

Описание

A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.

A stack buffer overflow flaw was found in the gsl package due to a lack of validation of the user controlled fraction parameter. This issue may allow an attacker to craft malicious input, leading to a segmentation fault and further Denial of Service. Since the buffer overflow happens when reading data from the input array, it's very unlikely to achieve arbitrary code execution using this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gslOut of support scope
Red Hat Enterprise Linux 7gslOut of support scope
Red Hat Enterprise Linux 8gslWill not fix
Red Hat Enterprise Linux 8inkscape:flatpak/gslWill not fix
Red Hat Enterprise Linux 9gslWill not fix
Red Hat Enterprise Linux 9inkscape:flatpak/gslWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2234896gsl: Stack buffer overflow in gsl_stats_quantile_from_sorted_data

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 3 лет назад

A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.

CVSS3: 6.5
nvd
около 3 лет назад

A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.

CVSS3: 6.5
msrc
больше 1 года назад

A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.

CVSS3: 6.5
debian
около 3 лет назад

A buffer overflow can occur when calculating the quantile value using ...

suse-cvrf
почти 3 года назад

Security update for gsl

6.5 Medium

CVSS3