Impact
An off‑by‑one error in the poptStuffArgs function of the popt command‑line option parsing library can corrupt internal program data. If a host application then processes the altered data unsafely, a local attacker may be able to execute arbitrary code. The weakness is an out‑of‑bounds write (CWE‑787).
Affected Systems
The vulnerability affects any system that uses the popt library, particularly host applications that repeatedly call poptStuffArgs or employ deep alias nesting. No specific vendor or product version information is provided in the CVE data.
Risk and Exploitability
The CVSS score of 2.5 indicates low severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV. Exploitation requires local access and depends on the host application processing the corrupted data unsafely. Overall risk is low to moderate, but local code execution is possible if the conditions are met.
OpenCVE Enrichment