vulnerability

Huawei EulerOS: CVE-2023-46049: llvm security update

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
03/27/2024
Added
06/26/2024
Modified
02/18/2025

Description

LLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a crafted .o file) to llvm-lto. NOTE: this is disputed because the relationship between pdflatex.fmt and any LLVM language front end is not explained, and because a crash of the llvm-lto application should be categorized as a usability problem.

Solution(s)

huawei-euleros-2_0_sp11-upgrade-llvmhuawei-euleros-2_0_sp11-upgrade-llvm-helphuawei-euleros-2_0_sp11-upgrade-llvm-libs
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.