7.5

CVE-2021-32422

dpic 2021.01.01 has a Global buffer overflow in theyylex() function in main.c and reads out of the bound array.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dpic ProjectDpic Version2021-01-01
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.469
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

https://gitlab.com/aplevich/dpic/-/commit/d317e4066c17f9ceb359b3af13264c32f6fb43cf
Third Party Advisory
https://gitlab.com/aplevich/dpic/-/issues/6
Third Party Advisory