CVE-2011-3631
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.69% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- hardlink project/hardlink · debian/debian linux · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/cve-2011-3631Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=645516Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3631Issue Tracking, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-3631Third Party Advisory
- https://access.redhat.com/security/cve/cve-2011-3631Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=645516Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3631Issue Tracking, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-3631Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.