Heap-Buffer Overflow in LIEF Core Component
CVE-2022-38306
7.8HIGH
What is CVE-2022-38306?
A heap-buffer overflow vulnerability has been identified in the LIEF project, specifically within the /core/CorePrPsInfo.tcc component. This flaw arises from improper handling of memory allocation, which could lead to a potential exploitation and unauthorized access to sensitive data. Users of affected versions should prioritize updates and consider implementing additional security measures to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
