vendor:
GNU Barcode
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: GNU Barcode
Affected Version From: 0.99
Affected Version To: 0.99
Patch Exists: NO
Related CWE:
CPE: a:gnu:barcode:0.99
Platforms Tested: Ubuntu 16.04.4
GNU Barcode 0.99 – Buffer Overflow
The vulnerability is caused due to a boundary error in the processing of an input file, which can be exploited to cause a buffer overflow when a user processes e.g. a specially crafted file. Successful exploitation could allow execution of arbitrary code on the affected machine.
Mitigation:
Apply the vendor's patch to fix the buffer overflow vulnerability.