Impact
A stack‑based buffer overflow exists in MCC’s Universal Library for Linux (uldaq). The flaw allows a crafted input to overflow a stack buffer, potentially exposing process memory or allowing an attacker to execute arbitrary code. The vulnerability aligns with CWE‑121 and is described by the vendor as capable of information disclosure or code execution.
Affected Systems
The issue affects all instances of MCC Universal Library for Linux (uldaq) version 1.2.1 and earlier, which are commonly deployed on Linux systems that integrate the library in user applications or server services.
Risk and Exploitability
The CVSS base score of 8.6 marks it as high severity. The EPSS score of less than 1% indicates a very low current likelihood of widespread exploitation, and the flaw is not catalogued in CISA’s KEV list. Based on the description, it is inferred that the attack vector requires an attacker to invoke the library with specially crafted data, which could be a local exploitation scenario or a remote one if the library is used by network‑exposed services. No public exploit is available, so manual exploitation may be needed.
OpenCVE Enrichment