CVE-2025-15614
ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.
Słabość
ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.
Źródła
- https://github.com/Genivia/ugrep
- https://github.com/Genivia/ugrep/blob/v7.5.0/src/zopen.c#L673
- https://github.com/Genivia/ugrep/commit/c12849a11264e2c81c860bf78ee9039772f307a4
- https://github.com/Genivia/ugrep/issues/511
- https://github.com/Genivia/ugrep/releases/tag/v7.6.0
- https://www.vulncheck.com/advisories/ugrep-before-7.6.0-heap-buffer-over-read-via-z-decompression
Znajdź błąd, zanim zrobi to atakujący.
Zaloguj się przez GitHub i uruchom pierwszy audyt w niecałą minutę. Plan darmowy nie wymaga karty kredytowej.