Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-42920
HistoryNov 07, 2022 - 1:15 p.m.

Out-of-bounds

2022-11-0713:15:00
PRIOn knowledge base
www.prio-n.com
11
apache commons bcel
out-of-bounds writing
arbitrary bytecode
attacker-controllable data
bytecode manipulation
security update

9.3 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.8%

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

CPENameOperatorVersion
commons_bcellt6.6.0
fedoraeq35
fedoraeq36
fedoraeq37