mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-29 05:56:59 +00:00
122 lines
4.5 KiB
JSON
122 lines
4.5 KiB
JSON
{
|
|
"data_version": "4.0",
|
|
"data_type": "CVE",
|
|
"data_format": "MITRE",
|
|
"CVE_data_meta": {
|
|
"ID": "CVE-2023-1190",
|
|
"ASSIGNER": "cna@vuldb.com",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "A vulnerability was found in xiaozhuai imageinfo up to 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file imageinfo.hpp. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. VDB-222362 is the identifier assigned to this vulnerability."
|
|
},
|
|
{
|
|
"lang": "deu",
|
|
"value": "Eine problematische Schwachstelle wurde in xiaozhuai imageinfo bis 3.0.3 ausgemacht. Dies betrifft einen unbekannten Teil der Datei imageinfo.hpp. Durch Manipulieren mit unbekannten Daten kann eine buffer overflow-Schwachstelle ausgenutzt werden. Der Angriff muss lokal passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
|
|
}
|
|
]
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-120 Buffer Overflow",
|
|
"cweId": "CWE-120"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "xiaozhuai",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "imageinfo",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "3.0.0"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "3.0.1"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "3.0.2"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "3.0.3"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"url": "https://vuldb.com/?id.222362",
|
|
"refsource": "MISC",
|
|
"name": "https://vuldb.com/?id.222362"
|
|
},
|
|
{
|
|
"url": "https://vuldb.com/?ctiid.222362",
|
|
"refsource": "MISC",
|
|
"name": "https://vuldb.com/?ctiid.222362"
|
|
},
|
|
{
|
|
"url": "https://github.com/xiaozhuai/imageinfo/issues/1",
|
|
"refsource": "MISC",
|
|
"name": "https://github.com/xiaozhuai/imageinfo/issues/1"
|
|
},
|
|
{
|
|
"url": "https://github.com/10cksYiqiyinHangzhouTechnology/imageinfo_poc",
|
|
"refsource": "MISC",
|
|
"name": "https://github.com/10cksYiqiyinHangzhouTechnology/imageinfo_poc"
|
|
}
|
|
]
|
|
},
|
|
"credits": [
|
|
{
|
|
"lang": "en",
|
|
"value": "10cksYiqiyinHangzhouTechnology (VulDB User)"
|
|
}
|
|
],
|
|
"impact": {
|
|
"cvss": [
|
|
{
|
|
"version": "3.1",
|
|
"baseScore": 4.8,
|
|
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
{
|
|
"version": "3.0",
|
|
"baseScore": 4.8,
|
|
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
{
|
|
"version": "2.0",
|
|
"baseScore": 4.3,
|
|
"vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
|
|
}
|
|
]
|
|
}
|
|
} |