SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-0459

flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a…

HIGH 7.5EPSS 4.77%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
4.77% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
westes/flex
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.