PT-2013-1883 · Swi+1 · Swi-Prolog+1

Jan Lieskovsky

+1

·

Publicado

2013-01-04

·

Atualizado

2018-03-04

·

CVE-2012-6090

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SWI-Prolog versions prior to 6.2.5 SWI-Prolog versions 6.3.x prior to 6.3.7
Description The issue is related to multiple stack-based buffer overflows in the expand function in os/pl-glob.c. This can be exploited by remote attackers using a crafted filename, potentially leading to a denial of service (application crash) or possibly the execution of arbitrary code.
Recommendations For SWI-Prolog versions prior to 6.2.5, update to version 6.2.5 or later. For SWI-Prolog versions 6.3.x prior to 6.3.7, update to version 6.3.7 or later.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1360
CVE-2012-6090

Produtos afetados

Alt Linux
Swi-Prolog