PT-2018-10653 · Md4C · Md4C

Chijinz

·

Published

2018-05-29

·

Updated

2018-06-29

·

CVE-2018-11546

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions md4c version 0.2.5
Description The issue is caused by a heap-based buffer over-read due to an off-by-one error in the md is named entity contents function.
Recommendations For md4c version 0.2.5, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11546

Affected Products

Md4C