USN-8777-1: GNU Bison vulnerability
Ubuntu issued USN-8777-1 fixing a GNU Bison flaw in HTML report generation that could allow attackers to execute arbitrary code.
Ubuntu Security Notice USN-8777-1 fixes a vulnerability in GNU Bison, which incorrectly handled grammar-defined configuration variables when generating HTML reports. An attacker could potentially leverage this issue to execute arbitrary code. Patched packages are available for supported Ubuntu releases; no CVE id is listed in the notice and no active exploitation is mentioned.
- GNU Bison mishandled grammar-defined configuration variables in HTML report generation.
- Issue could enable arbitrary code execution.
- Ubuntu released patched packages under USN-8777-1.
It was discovered that GNU Bison incorrectly handled grammar-defined configuration variables when generating HTML reports. An attacker could possibly use this issue to execute arbitrary code.
This source does not provide full text. Read it at ubuntu.com.