Vulnerability Description
The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted repository.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| C\/C\+\+ Advanced Lint Project | C\/C\+\+ Advanced Lint | < 1.9.0 |
Related Weaknesses (CWE)
References
- https://github.com/jbenden/vscode-c-cpp-flylint/compare/v1.8.2...v1.9.0PatchThird Party Advisory
- https://marketplace.visualstudio.com/items?itemName=jbenden.c-cpp-flylintProductThird Party Advisory
- https://vuln.ryotak.me/advisories/16Third Party Advisory
- https://github.com/jbenden/vscode-c-cpp-flylint/compare/v1.8.2...v1.9.0PatchThird Party Advisory
- https://marketplace.visualstudio.com/items?itemName=jbenden.c-cpp-flylintProductThird Party Advisory
- https://vuln.ryotak.me/advisories/16Third Party Advisory
FAQ
What is CVE-2021-28953?
CVE-2021-28953 is a vulnerability with a CVSS score of 7.8 (HIGH). The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted repository.
How severe is CVE-2021-28953?
CVE-2021-28953 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-28953?
Check the references section above for vendor advisories and patch information. Affected products include: C\/C\+\+ Advanced Lint Project C\/C\+\+ Advanced Lint.