Back

CRITICAL

pkgconf: 1 byte out of bounds read for 0 length keys

Published Aug 20, 2018

Description

pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow. This attack appear to be exploitable via specially crafted .pc file. This vulnerability appears to have been fixed in 1.5.3.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 20, 2018
Updated Sep 17, 2024
Reserved Aug 20, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 24, 2018
ENISA EUVD
Assigner mitre
Published Aug 20, 2018
Updated Sep 17, 2024
Exploited since n/a
EUVD-2018-1891