Lucene search

K
cve[email protected]CVE-2014-9488
HistoryApr 14, 2015 - 6:59 p.m.

CVE-2014-9488

2015-04-1418:59:02
CWE-119
web.nvd.nist.gov
34
cve-2014-9488
gnu less
remote attackers
malformed utf-8 characters
out-of-bounds read
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

Low

0.013 Low

EPSS

Percentile

85.9%

The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.

Affected configurations

NVD
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
Node
gnulessRange471

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

Low

0.013 Low

EPSS

Percentile

85.9%