7.5

CVE-2021-27799

Exploit
ean_leading_zeroes in backend/upcean.c in Zint Barcode Generator 2.9.1 has a stack-based buffer overflow that is reachable from the C API through an application that includes the Zint Barcode Generator library code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZintBarcode Generator Version2.9.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.37% 0.816
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://zint.org.uk/Manual.aspx?type=p&page=3
Vendor Advisory
http://zint.org.uk/Manual.aspx?type=p&page=4
Vendor Advisory
http://zint.org.uk/Manual.aspx?type=p&page=5
Vendor Advisory
https://sourceforge.net/p/zint/code/ci/7f8c8114f31c09a986597e0ba63a49f96150368a/
Patch
Third Party Advisory
https://sourceforge.net/p/zint/tickets/218/
Third Party Advisory
Exploit