Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-31636
HistoryMay 03, 2024 - 12:00 a.m.

CVE-2024-31636

2024-05-0300:00:00
ubuntu.com
ubuntu.com
5
lief
v0.14.1
local attacker
sensitive information

CVSS3

3.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

15.5%

An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive
information via the name parameter of the machd_reader.c component.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchlief< anyUNKNOWN
ubuntu22.04noarchlief< anyUNKNOWN

CVSS3

3.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

15.5%