CVE-2011-3630
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.66% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- hardlink project/hardlink · debian/debian linux · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/cve-2011-3630Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=645516Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3630Issue Tracking, Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-3630Third Party Advisory
- https://www.openwall.com/lists/oss-security/2011/10/20/6Mailing List, Third Party Advisory
- https://access.redhat.com/security/cve/cve-2011-3630Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=645516Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3630Issue Tracking, Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-3630Third Party Advisory
- https://www.openwall.com/lists/oss-security/2011/10/20/6Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.