An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, which allows an attacker to cause a denial of service by passing an improper list to an application that calls "length" on it.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-chicken | Aug 30, 2017 | Jun 1, 2017 | |
| Debian | debian-upgrade-chicken | Jul 30, 2024 | Jun 1, 2017 | |
| Freebsd | freebsd-upgrade-package-chicken | Aug 14, 2018 | Aug 12, 2018 | |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Jun 1, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub