Описание
An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.
Отчет
This is a Low impact vulnerability where a size_t underflow in the popt library's help formatting function can occur when an application's option table is displayed in a narrow terminal with large option widths. This could potentially lead to memory allocation failures or out-of-bounds writes, but requires specific user interaction and terminal conditions, limiting its exploitability and overall risk.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | popt | Fix deferred | ||
| Red Hat Enterprise Linux 6 | popt | Out of support scope | ||
| Red Hat Enterprise Linux 7 | popt | Fix deferred | ||
| Red Hat Enterprise Linux 8 | popt | Fix deferred | ||
| Red Hat Enterprise Linux 9 | popt | Fix deferred | ||
| Red Hat Hardened Images | popt | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
2.2 Low
CVSS3
Связанные уязвимости
(An integer underflow was found in the popt library when formatting hel ...)
An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.
An integer underflow was found in the popt library when formatting hel ...
An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.
EPSS
2.2 Low
CVSS3