Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-40897

Опубликовано: 26 июл. 2024
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10orcNot affected
Red Hat Enterprise Linux 7orcOut of support scope
Red Hat Enterprise Linux 8orcFixedRHSA-2024:530613.08.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportorcFixedRHSA-2024:588227.08.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportorcFixedRHSA-2024:615903.09.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceorcFixedRHSA-2024:615903.09.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsorcFixedRHSA-2024:615903.09.2024
Red Hat Enterprise Linux 9orcFixedRHSA-2024:618403.09.2024
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsorcFixedRHSA-2024:562920.08.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportorcFixedRHSA-2024:563820.08.2024

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2300010orc: Stack-based buffer overflow vulnerability in ORC

EPSS

Процентиль: 10%
0.00037
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 1 года назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
nvd
около 1 года назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 6.7
debian
около 1 года назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC ...

suse-cvrf
6 месяцев назад

Security update for orc

EPSS

Процентиль: 10%
0.00037
Низкий

6.7 Medium

CVSS3