1 results (0.003 seconds)

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison. GNU Bison versión 3.7, presenta una vulnerabilidad de uso de la memoria previamente liberada (UAF). Un atacante local puede ejecutar bison con un archivo de entrada diseñado que contiene un byte NULL, lo que podría desencadenar un UAF y, por lo tanto, causar un bloqueo del sistema • https://github.com/akimd/bison/commit/be95a4fe2951374676efc9454ffee8638faaf68d https://github.com/akimd/bison/compare/v3.7...v3.7.1 https://lists.gnu.org/r/bug-bison/2020-07/msg00051.html • CWE-416: Use After Free •