pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow. This attack appear to be exploitable via specially crafted .pc file. This vulnerability appears to have been fixed in 1.5.3.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-08-20T20:00:00Z

Updated: 2024-09-17T00:05:27.313Z

Reserved: 2018-08-20T00:00:00Z

Link: CVE-2018-1000221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-08-20T20:29:01.190

Modified: 2018-10-15T16:04:53.377

Link: CVE-2018-1000221

cve-icon Redhat

Severity : Low

Publid Date: 2018-08-24T00:00:00Z

Links: CVE-2018-1000221 - Bugzilla