7.8

CVE-2021-30498

Exploit

A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.

Data is provided by the National Vulnerability Database (NVD)
Libcaca ProjectLibcaca Version0.99 Updatebeta14
Libcaca ProjectLibcaca Version0.99 Updatebeta15
Libcaca ProjectLibcaca Version0.99 Updatebeta16
Libcaca ProjectLibcaca Version0.99 Updatebeta17
Libcaca ProjectLibcaca Version0.99 Updatebeta18
Libcaca ProjectLibcaca Version0.99 Updatebeta19
FedoraprojectFedora Version34
FedoraprojectFedora Version35
FedoraprojectFedora Version36
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.362
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.