Vulnerability Description
A flaw was found in dmg2img through 20170502. dmg2img did not validate the size of the read buffer during memcpy() inside the main() function. This possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dmg2Img Project | Dmg2Img | <= 20170502 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1959585Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1959585Issue TrackingThird Party Advisory
FAQ
What is CVE-2021-3548?
CVE-2021-3548 is a vulnerability with a CVSS score of 7.1 (HIGH). A flaw was found in dmg2img through 20170502. dmg2img did not validate the size of the read buffer during memcpy() inside the main() function. This possibly leads to memory layout information leaking ...
How severe is CVE-2021-3548?
CVE-2021-3548 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3548?
Check the references section above for vendor advisories and patch information. Affected products include: Dmg2Img Project Dmg2Img.