CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS
Percentile
93.1%
Jason Duell reports:
Cscope contains an alarming number of buffer overflow
vulnerabilities. By a rough count, there are at least 48 places
where we blindly sprintf() a file name into a fixed-length buffer
of size PATHLEN without checking to see if the file’s name
is <= PATHLEN. We do similar things with environment variable
values.