Описание
When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).
A use-after-free flaw was found in the byacc package. When processing a specially crafted file, malloc incorrectly accesses the released memory.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | byacc | Out of support scope | ||
| Red Hat Enterprise Linux 7 | byacc | Will not fix | ||
| Red Hat Enterprise Linux 8 | byacc | Not affected | ||
| Red Hat Enterprise Linux 9 | byacc | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2183006byacc: malloc incorrectly accessing released memory leads to use after free
4.4 Medium
CVSS3
Связанные уязвимости
CVSS3: 7.8
nvd
около 3 лет назад
When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).
CVSS3: 9.8
github
около 3 лет назад
When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).
4.4 Medium
CVSS3