Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade cscope | Dec 1, 2016 | May 7, 2009 |
| Debian | — | Upgrade cscope | Jul 30, 2024 | May 7, 2009 |
| Freebsd | — | Upgrade cscope | Dec 10, 2025 | Jun 16, 2009 |
| Gentoo Linux | — | Upgrade dev-util/cscope. | Oct 30, 2017 | May 7, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub