ZeroHour

CVE-2018-12097

CVSS 3.0
5.5 medium
EPSS
<1%p47
Published
()
Modified
Description

The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub

Vendors
liblnk project
Products
liblnk
Weakness
CWE-125, CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.