4 results (0.006 seconds)

CVSS: 5.5EPSS: 0%CPEs: 6EXPL: 0

24 Nov 2020 — In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow). En musl libc versiones hasta 1.2.1, wcsnrtombs maneja inapropiadamente combinaciones particulares de tamaño de búfer de destino y límite de caracteres de origen, como es demostrado por un acceso de escritura no válido (desbordamiento de búfer) It was discovered that musl did not handle certain i386 math functions proper... • http://www.openwall.com/lists/oss-security/2020/11/20/4 • CWE-787: Out-of-bounds Write •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

19 Oct 2017 — musl libc before 1.1.17 has a buffer overflow via crafted DNS replies because dns_parse_callback in network/lookup_name.c does not restrict the number of addresses, and thus an attacker can provide an unexpected number by sending A records in a reply to an AAAA query. musl libc, en versiones anteriores a la 1.1.17, tiene un desbordamiento de búfer mediante respuestas DNS manipuladas, debido a que dns_parse_callback en network/lookup_name.c no restringe el número de direcciones y, por lo tanto, un atacante p... • http://git.musl-libc.org/cgit/musl/commit/?id=45ca5d3fcb6f874bf5ba55d0e9651cef68515395 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.8EPSS: 1%CPEs: 1EXPL: 0

02 Jan 2017 — Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write. Múltiples desbordamientos de enteros en la librería TRE y musl libc permiten a atacantes provocar corrupción de memoria a través de un gran número de (1) estados o (2) etiquetas, lo que desencadena una escritura fuera de límites. Multiple vulnerabilities have been found in TRE, the worst of which could result in the arbitr... • http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html • CWE-190: Integer Overflow or Wraparound •

CVSS: 9.8EPSS: 1%CPEs: 1EXPL: 0

31 Aug 2012 — Stack-based buffer overflow in fprintf in musl before 0.8.8 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string to an unbuffered stream such as stderr. Desbordamiento de búfer basado en pila en fprintf de musl anteriores a v0.8.8 permite a atacantes dependientes del contexto provocar una denegación del servicio (caída de la aplicación) o probablmente ejecutar código de su elección mediante una cadena de caracteres larga en ... • http://www.etalabs.net/musl/download.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •