Denial of Service Vulnerability in GNU libcdio Affected by Crafted ISO File
CVE-2017-18198
8.8HIGH
Summary
The vulnerability in GNU libcdio allows remote attackers to exploit the 'print_iso9660_recurse' function in 'iso-info.c', resulting in a denial of service through a heap-based buffer over-read. By providing a maliciously crafted ISO file, an attacker can potentially disrupt service or cause unexpected behavior in applications utilizing the affected library. Users are advised to upgrade to version 1.0.0 or later to mitigate the risk associated with this vulnerability.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved