Heap-based Buffer Overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows attacker to read out of bound memory
CVSS Details
- CVSS 4.0 Base Score: 5.1 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade iniparser-debuginfoUpgrade iniparser-develUpgrade iniparser | Apr 2, 2025 | Feb 19, 2025 |
| Debian | — | No solution existsUpgrade iniparser | May 15, 2025 | Feb 19, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 19, 2025 |
| Suse | — | Upgrade libiniparser-develUpgrade libiniparser0Upgrade libiniparser1Upgrade libiniparser4Upgrade libiniparser0-32bitUpgrade libiniparser1-32bit | Mar 11, 2025 | Feb 19, 2025 |
| Ubuntu | — | Upgrade libiniparser1 | Feb 25, 2025 | Feb 19, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Feb 19, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub