PT-2017-3183 · Bchunk+1 · Bchunk+1
Wen Bin
·
Publicado
2017-09-09
·
Atualizado
2024-08-19
·
CVE-2017-15955
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
bchunk versions 1.2.0 through 1.2.1
Description
The issue is related to pointer dereference errors. It can be exploited by a remote attacker using a specially crafted .cue file, potentially causing the application to crash. The problem arises when processing a malformed CUE file, leading to an access violation.
Recommendations
For versions 1.2.0 and 1.2.1, consider avoiding the use of malformed .cue files until a patch is available.
As a temporary workaround, restrict the processing of .cue files to minimize the risk of exploitation.
Correção
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Bchunk