PT-2022-27182 · Picoc · Picoc

Halcy0Nic

·

Published

2022-11-08

·

Updated

2022-11-08

·

CVE-2022-44318

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PicoC version 3.2.2
Description A heap buffer overflow was discovered in the StringStrcat function in cstdlib/string.c when called from ExpressionParseFunctionCall. This issue affects PicoC and is related to the StringStrcat function, which is used for string concatenation.
Recommendations For PicoC version 3.2.2, consider disabling the StringStrcat function until a patch is available to prevent potential exploitation of the heap buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-44318

Affected Products

Picoc