PT-2013-1883 · Swi+1 · Swi-Prolog+1
Jan Lieskovsky
+1
·
Publicado
2013-01-04
·
Atualizado
2018-03-04
·
CVE-2012-6090
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SWI-Prolog versions prior to 6.2.5
SWI-Prolog versions 6.3.x prior to 6.3.7
Description
The issue is related to multiple stack-based buffer overflows in the expand function in os/pl-glob.c. This can be exploited by remote attackers using a crafted filename, potentially leading to a denial of service (application crash) or possibly the execution of arbitrary code.
Recommendations
For SWI-Prolog versions prior to 6.2.5, update to version 6.2.5 or later.
For SWI-Prolog versions 6.3.x prior to 6.3.7, update to version 6.3.7 or later.
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Swi-Prolog