CRITICAL
pkgconf: 1 byte out of bounds read for 0 length keys
Published Aug 20, 2018
9.8
CRITICALCVSS 3.0
EPSS 1.35%
Description
pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow. This attack appear to be exploitable via specially crafted .pc file. This vulnerability appears to have been fixed in 1.5.3.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://access.redhat.com/security/cve/CVE-2018-1000221 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1622242 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-1891 Advisory
- https://git.dereferenced.org/pkgconf/pkgconf/pulls/3 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000221
- https://www.cve.org/CVERecord?id=CVE-2018-1000221
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1000221 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1622242 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-1891 | Advisory | |
| https://git.dereferenced.org/pkgconf/pkgconf/pulls/3 | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000221 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000221 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 20, 2018
Updated Sep 17, 2024
Reserved Aug 20, 2018
Link CVE-2018-1000221
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-1891 Assigner mitre
Published Aug 20, 2018
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2018-1891