CVE-2012-4025

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
19/07/2012
Last modified:
11/04/2025

Description

Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:squashfs_project:squashfs:*:*:*:*:*:*:*:* 4.2 (including)