Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.
References
Link | Resource |
---|---|
https://github.com/bfabiszewski/libmobi/commit/fb1ab50e448ddbed746fd27ae07469bc506d838b | Patch Third Party Advisory |
https://huntr.dev/bounties/9a90ffa1-38f5-4685-9c00-68ba9068ce3d | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
History
11 May 2022, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-125 | |
CVSS |
v2 : v3 : |
v2 : 3.6
v3 : 7.1 |
CPE | cpe:2.3:a:libmobi_project:libmobi:*:*:*:*:*:*:*:* | |
References | (CONFIRM) https://huntr.dev/bounties/9a90ffa1-38f5-4685-9c00-68ba9068ce3d - Exploit, Issue Tracking, Patch, Third Party Advisory | |
References | (MISC) https://github.com/bfabiszewski/libmobi/commit/fb1ab50e448ddbed746fd27ae07469bc506d838b - Patch, Third Party Advisory |
29 Apr 2022, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-04-29 11:15
Updated : 2024-02-04 22:29
NVD link : CVE-2022-1534
Mitre link : CVE-2022-1534
CVE.ORG link : CVE-2022-1534
JSON object : View
Products Affected
libmobi_project
- libmobi