Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-20229

Опубликовано: 28 мар. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.8

Описание

MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can craft malicious input that overflows the stack buffer and execute a return-oriented programming chain to spawn a shell with application privileges.

РелизСтатусПримечание
devel

not-affected

1.3.4.20260129-1
esm-infra-legacy/trusty

needed

esm-infra-legacy/xenial

needed

esm-infra/bionic

needed

esm-infra/focal

not-affected

1.3.4.20200120-2
esm-infra/xenial

ignored

end of ESM support, was needed
jammy

not-affected

1.3.4.20200120-3
noble

not-affected

1.3.4.20240123-1build1
questing

not-affected

1.3.4.20240123-1build1
resolute

not-affected

1.3.4.20260129-1

Показывать по

EPSS

Процентиль: 47%
0.00602
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
6 месяцев назад

MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can craft malicious input that overflows the stack buffer and execute a return-oriented programming chain to spawn a shell with application privileges.

CVSS3: 9.8
debian
6 месяцев назад

MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnera ...

CVSS3: 9.8
github
6 месяцев назад

MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can craft malicious input that overflows the stack buffer and execute a return-oriented programming chain to spawn a shell with application privileges.

EPSS

Процентиль: 47%
0.00602
Низкий

9.8 Critical

CVSS3