CVE-2013-2075

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
31/10/2019
Last modified:
07/11/2023

Description

Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken through 4.8.0.3 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value. NOTE: this issue exists because of an incomplete fix for CVE-2012-6122.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:call-cc:chicken:*:*:*:*:*:*:*:* 4.8.0.3 (including)