CVE-2006-0459
flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.77% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- westes/flex
- Source
- secalert@redhat.com
References
- http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?downloadProduct
- http://secunia.com/advisories/19071Patch, Vendor Advisory
- http://secunia.com/advisories/19126Vendor Advisory
- http://secunia.com/advisories/19228Vendor Advisory
- http://secunia.com/advisories/19424Patch, Vendor Advisory
- http://securityreason.com/securityalert/570Third Party Advisory
- http://sourceforge.net/mailarchive/forum.php?thread_name=20060223020346.GA11231%40tabitha.home.tldz.org&forum_name=flex-announceRelease Notes
- http://www.gentoo.org/security/en/glsa/glsa-200603-07.xmlThird Party Advisory
- http://www.osvdb.org/23440Broken Link, Patch
- http://www.securityfocus.com/bid/16896Patch, Third Party Advisory, VDB Entry
- http://www.us.debian.org/security/2006/dsa-1020Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0770Broken Link, URL Repurposed
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24995VDB Entry
- https://usn.ubuntu.com/260-1/Third Party Advisory
- http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?downloadProduct
- http://secunia.com/advisories/19071Patch, Vendor Advisory
- http://secunia.com/advisories/19126Vendor Advisory
- http://secunia.com/advisories/19228Vendor Advisory
- http://secunia.com/advisories/19424Patch, Vendor Advisory
- http://securityreason.com/securityalert/570Third Party Advisory
- http://sourceforge.net/mailarchive/forum.php?thread_name=20060223020346.GA11231%40tabitha.home.tldz.org&forum_name=flex-announceRelease Notes
- http://www.gentoo.org/security/en/glsa/glsa-200603-07.xmlThird Party Advisory
- http://www.osvdb.org/23440Broken Link, Patch
- http://www.securityfocus.com/bid/16896Patch, Third Party Advisory, VDB Entry
- http://www.us.debian.org/security/2006/dsa-1020Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0770Broken Link, URL Repurposed
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24995VDB Entry
- https://usn.ubuntu.com/260-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.