5.5
CVE-2023-45897
- EPSS 0.38%
- Veröffentlicht 28.10.2023 21:15:07
- Zuletzt bearbeitet 21.11.2024 08:27:34
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Namjaejeon ≫ Exfatprogs Version < 1.2.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.297 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://dfir.ru/2023/11/01/cve-2023-45897-a-vulnerability-in-the-linux-exfat-userspace-tools/
https://github.com/exfatprogs/exfatprogs/commit/22d0e43e8d24119cbfc6efafabb0dec6517a86c4
https://github.com/exfatprogs/exfatprogs/commit/4abc55e976573991e6a1117bb2b3711e59da07ae
https://github.com/exfatprogs/exfatprogs/commit/ec78688e5fb5a70e13df82b4c0da1e6228d3ccdf
https://github.com/exfatprogs/exfatprogs/releases/tag/1.2.2
https://lists.debian.org/debian-lts-announce/2024/09/msg00003.html