PT-2021-4273 · Dmg2Img+1 · Dmg2Img+1

Anshunkang Zhou

+1

·

Published

2021-05-26

·

Updated

2021-06-04

·

CVE-2021-3548

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions dmg2img versions through 20170502
Description A flaw was found in dmg2img where it did not validate the size of the read buffer during memcpy() inside the main() function. This possibly leads to memory layout information leaking in the data, which might be used in a chain of vulnerability to reach code execution. The exploitation of this flaw could allow a remote attacker to access confidential data and cause a denial of service.
Recommendations For versions through 20170502, as a temporary workaround, consider restricting the use of the main() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04881
CVE-2021-3548

Affected Products

Debian
Dmg2Img