SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2675

Multiple integer overflows in the (1) CallMalloc (malloc) and (2) nedpcalloc (calloc) functions in nedmalloc (nedmalloc.c) before 1.10 beta2 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a…

MEDIUM 4.3EPSS 1.32%

Does this matter?

Lower severity and a low EPSS score (1.32%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple integer overflows in the (1) CallMalloc (malloc) and (2) nedpcalloc (calloc) functions in nedmalloc (nedmalloc.c) before 1.10 beta2 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.32% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-189
Affected
nedprod/nedmalloc
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.