The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values of user SID data size, strings size, or data size. NOTE: the vendor has disputed this as described in libyal/libevt issue 5 on GitHub
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-03-18T03:00:00

Updated: 2024-08-05T07:02:26.033Z

Reserved: 2018-03-17T00:00:00

Link: CVE-2018-8754

cve-icon Vulnrichment

Updated: 2024-08-05T07:02:26.033Z

cve-icon NVD

Status : Modified

Published: 2018-03-18T03:29:00.277

Modified: 2024-08-05T07:15:56.347

Link: CVE-2018-8754

cve-icon Redhat

No data.