VulnerabilityModified
CVE-2012-6123
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
MEDIUM 6.5EPSS 1.27%
Does this matter?
Lower severity and a low EPSS score (1.27%). Track it; it rarely justifies an emergency change on its own.
Description
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- call-cc/chicken · debian/debian linux
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2013/02/08/2Mailing List, Third Party Advisory
- https://access.redhat.com/security/cve/cve-2012-6123Broken Link
- https://security-tracker.debian.org/tracker/CVE-2012-6123Third Party Advisory
- http://www.openwall.com/lists/oss-security/2013/02/08/2Mailing List, Third Party Advisory
- https://access.redhat.com/security/cve/cve-2012-6123Broken Link
- https://security-tracker.debian.org/tracker/CVE-2012-6123Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.