print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted iso file.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libcdioUpgrade libcdio-debuginfoUpgrade libcdio-devel | Apr 27, 2020 | Feb 24, 2018 |
| Centos_linux | — | Upgrade libcdio-debuginfoUpgrade libcdio-develUpgrade libcdio | Aug 28, 2019 | Feb 24, 2018 |
| Debian | — | Upgrade libcdio | Jul 30, 2024 | Feb 24, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libcdio | Dec 31, 2018 | Feb 24, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libcdio | Dec 11, 2018 | Feb 24, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libcdio | Jul 2, 2019 | Feb 24, 2018 |
| Oracle_linux | — | Upgrade libcdioUpgrade libcdio-devel | Nov 6, 2018 | Feb 27, 2018 |
| Redhat_linux | — | No solution existsUpgrade libcdio-debuginfoUpgrade libcdio-develUpgrade libcdio | Oct 31, 2018 | Feb 24, 2018 |
| Suse | — | Upgrade libiso9660-11Upgrade libcdio19Upgrade libudf0Upgrade libcdio-develUpgrade libcdio++0 | Feb 4, 2022 | Feb 24, 2018 |
| Ubuntu | — | Upgrade libiso9660-8 (Ubuntu Pro)Upgrade libcdio-paranoia1 (Ubuntu Pro)Upgrade libcdio-utils (Ubuntu Pro)Upgrade libcdio13 (Ubuntu Pro)Upgrade libudf0 (Ubuntu Pro)Upgrade libcdio-cdda1 (Ubuntu Pro) | Aug 10, 2022 | Feb 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub