CVE-2018-1000221: Buffer Overflow
pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow. This attack appear to be exploitable via specially crafted .pc file. This vulnerability appears to have been fixed in 1.5.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000221?
CVE-2018-1000221 has a medium severity rating due to its potential to cause a buffer overflow.
How do I fix CVE-2018-1000221?
To fix CVE-2018-1000221, upgrade pkgconf to version 1.5.3 or later.
What versions are affected by CVE-2018-1000221?
CVE-2018-1000221 affects pkgconf versions from 1.5.0 to 1.5.2 inclusive.
What could be the impact of exploiting CVE-2018-1000221?
Exploiting CVE-2018-1000221 could lead to a buffer overflow, potentially resulting in arbitrary code execution.
Can CVE-2018-1000221 be exploited remotely?
CVE-2018-1000221 can be exploited via specially crafted .pc files, which may be delivered remotely.