Lucene search

K

Squashfs Security Vulnerabilities

cve
cve

CVE-2012-4024

Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option). NOTE: probably in most cases, the list file is a trusted file constr...

7.9AI Score

0.032EPSS

2012-07-19 07:55 PM
32
cve
cve

CVE-2012-4025

Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

7.8AI Score

0.038EPSS

2012-07-19 07:55 PM
35
cve
cve

CVE-2015-4645

Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.

5.5CVSS

6.2AI Score

0.011EPSS

2017-03-17 02:59 PM
51
cve
cve

CVE-2015-4646

(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.

7.5CVSS

7AI Score

0.006EPSS

2017-04-13 05:59 PM
43