PT-2026-48115 · Petdance+5 · App::Ack+2
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
App::Ack versions prior to 3.10.0
Description
Memory exhaustion can occur when the software searches the directory hierarchy for a project
.ackrc file and loads its options. The context options -B and -C accept any positive integer, and the software sizes the before-context buffer based on that value. Consequently, a setting such as --before-context=100000000 in a .ackrc file committed to an untrusted repository can cause the application to abort due to an out-of-memory condition.Recommendations
Update to version 3.10.0 or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
App::Ack
Ack
Ack3