Lucene search

K
osvGoogleOSV:GHSA-5CQM-CRXM-6QPV
HistoryDec 14, 2021 - 9:36 p.m.

Buffer overrun in CGI.escape_html

2021-12-1421:36:20
Google
osv.dev
37

0.011 Low

EPSS

Percentile

84.1%

A buffer overrun vulnerability was discovered in CGI.escape_html. This can lead to a buffer overflow when a user passes a very large string (> 700 MB) to CGI.escape_html on a platform where long type takes 4 bytes, typically, Windows.

CPENameOperatorVersion
cgieq0.1.0
cgieq0.2.0
cgieq0.3.0

References