CVE-2018-8754

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
18/03/2018
Last modified:
05/08/2024

Description

The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values of user SID data size, strings size, or data size. NOTE: the vendor has disputed this as described in libyal/libevt issue 5 on GitHub

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libevt_project:libevt:*:*:*:*:*:*:*:* 20180317 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*