CVE-2021-21813

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
13/08/2021
Last modified:
06/10/2022

Description

Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to memcpy copying the path provided by the user into a staticly sized buffer without any length checks resulting in a stack-buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:att:xmill:0.7:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools