Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a string that is inconsistent with the expected number of fields.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libhx | Jul 30, 2024 | Aug 24, 2010 |
| Suse | — | Upgrade libHX28-32bitUpgrade libHX13Upgrade libHX28Upgrade libHX13-x86Upgrade libHX13-32bitUpgrade libHX-develUpgrade libHX32 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libhx22Upgrade libhx18Upgrade libhx10Upgrade libhx14 | Nov 8, 2024 | Aug 24, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub