Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-46049
HistoryMar 27, 2024 - 12:00 a.m.

CVE-2023-46049

2024-03-2700:00:00
mitre
github.com
1
cve-2023-46049
llvm 15.0.0
null pointer
parseonemetadata
pdflatex.fmt
.o file
llvm-lto
usability problem

AI Score

6.6

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

LLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a crafted .o file) to llvm-lto. NOTE: this is disputed because the relationship between pdflatex.fmt and any LLVM language front end is not explained, and because a crash of the llvm-lto application should be categorized as a usability problem.

AI Score

6.6

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-46049