Vulnerability Description
Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program users to execute arbitrary code via crafted data. For example, a tape head may have an unexpected location after the processing of input composed of As and Bs (instead of 0s and 1s). NOTE: the discoverer states "this vulnerability has no real-world implications."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mit | Universal Turing Machine | - |
Related Weaknesses (CWE)
References
- https://arxiv.org/abs/2105.02124Third Party Advisory
- https://github.com/intrinsic-propensity/turing-machineExploitThird Party Advisory
- https://arxiv.org/abs/2105.02124Third Party Advisory
- https://github.com/intrinsic-propensity/turing-machineExploitThird Party Advisory
FAQ
What is CVE-2021-32471?
CVE-2021-32471 is a vulnerability with a CVSS score of 7.8 (HIGH). Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program users to execute arbitrary code via crafted data. For example, a tape head may hav...
How severe is CVE-2021-32471?
CVE-2021-32471 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-32471?
Check the references section above for vendor advisories and patch information. Affected products include: Mit Universal Turing Machine.