SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3548

This possibly leads to memory layout information leaking in the data.

HIGH 7.1EPSS 0.91%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A flaw was found in dmg2img through 20170502. dmg2img did not validate the size of the read buffer during memcpy() inside the main() function. This possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.

CVSS 3.1
7.1 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
EPSS
0.91% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
dmg2img project/dmg2img
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.