VulnerabilityModified
CVE-2020-35357
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6.
MEDIUM 6.5EPSS 0.97%
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- gnu/gnu scientific library · debian/debian linux
- Source
- cve@mitre.org
References
- https://git.savannah.gnu.org/cgit/gsl.git/commit/?id=989a193268b963aa1047814f7f1402084fb7d859Mailing List, Patch
- https://lists.debian.org/debian-lts-announce/2023/09/msg00023.htmlMailing List, Third Party Advisory
- https://savannah.gnu.org/bugs/?59624Patch
- https://git.savannah.gnu.org/cgit/gsl.git/commit/?id=989a193268b963aa1047814f7f1402084fb7d859Mailing List, Patch
- https://lists.debian.org/debian-lts-announce/2023/09/msg00023.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/12/msg00006.html
- https://savannah.gnu.org/bugs/?59624Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.