Heap-Buffer Overflow in LIEF Core Component
CVE-2022-38306

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
13 September 2022

What is CVE-2022-38306?

A heap-buffer overflow vulnerability has been identified in the LIEF project, specifically within the /core/CorePrPsInfo.tcc component. This flaw arises from improper handling of memory allocation, which could lead to a potential exploitation and unauthorized access to sensitive data. Users of affected versions should prioritize updates and consider implementing additional security measures to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-38306 : Heap-Buffer Overflow in LIEF Core Component