PT-2022-27181 · Picoc · Picoc

Halcy0Nic

·

Published

2022-11-08

·

Updated

2022-11-08

·

CVE-2022-44317

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PicoC version 3.2.2
Description A heap buffer overflow was discovered in the StdioOutPutc function in stdlib/stdio.c when called from ExpressionParseFunctionCall. This issue affects the StdioOutPutc function, which is part of the PicoC library.
Recommendations For PicoC version 3.2.2, consider disabling the StdioOutPutc function or restricting its use until a patch is available to prevent potential exploitation of the heap buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-44317

Affected Products

Picoc