PT-2019-15050 · Libyal+1 · Libfwsi+1
CVE-2019-17263
·
Publicado
2019-10-06
·
Atualizado
2024-08-05
CVSS v3.1
3.3
Baixa
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
libyal libfwsi versions prior to 20191006
Description
The issue is related to a heap-based buffer over-read in the libfwsi extension block copy from byte stream function in libfwsi extension block.c. This occurs because the rejection of an unsupported size only considers values less than 6, even though values of 6 and 7 are also unsupported. The vendor has disputed this issue as described in the GitHub issue.
Recommendations
For versions prior to 20191006, update to a version 20191006 or later to resolve the issue. As a temporary workaround, consider restricting the input to the libfwsi extension block copy from byte stream function to prevent exploitation.
Exploit
Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Libfwsi