CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
Percentile
91.9%
Integer overflow in the queue_init function in unsquashfs.c in unsquashfs
in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary
code via a crafted block_log field in the superblock of a .sqsh file,
leading to a heap-based buffer overflow.
sourceforge.net/mailarchive/forum.php?thread_name=CAAoG81HL9oP8roPLLhftTSXTzSD%2BZcR66PRkVU%3Df76W3Mjde_w%40mail.gmail.com&forum_name=squashfs-devel
www.openwall.com/lists/oss-security/2012/07/19/6
launchpad.net/bugs/cve/CVE-2012-4025
nvd.nist.gov/vuln/detail/CVE-2012-4025
security-tracker.debian.org/tracker/CVE-2012-4025
www.cve.org/CVERecord?id=CVE-2012-4025