Buffer Overflow Vulnerability in Sharutils by GNU
CVE-2018-1000097

7.8HIGH

Key Information:

Vendor
Debian
Vendor
CVE Published:
13 March 2018

Summary

The unshar command in Sharutils version 4.15.2 harbors a Buffer Overflow vulnerability identified in the file unshar.c at line 75 within the function looks_like_c_code. This flaw arises from insufficient validation of the buffer containing input lines. When a user executes the unshar command on a specially crafted file, it can lead to potential code execution, posing significant security risks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.