Описание
A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.
Отчет
This flaw has Low impact as it requires a host application to repeatedly call poptStuffArgs or use deep alias nesting, leading to an off-by-one error. Exploitation is only possible if the host application then unsafely processes the corrupted poptContext data, such as sinking it into exec, system, popen, or dlopen.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | popt | Affected | ||
| Red Hat Enterprise Linux 6 | popt | Out of support scope | ||
| Red Hat Enterprise Linux 7 | popt | Fix deferred | ||
| Red Hat Enterprise Linux 8 | popt | Fix deferred | ||
| Red Hat Enterprise Linux 9 | popt | Fix deferred | ||
| Red Hat Hardened Images | popt | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
2.5 Low
CVSS3
Связанные уязвимости
A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.
A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.
A flaw was found in popt, a command-line option parsing library. An of ...
A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.
EPSS
2.5 Low
CVSS3