TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.
References
| Link | Resource |
|---|---|
| https://github.com/cxong/tinydir/security/advisories/GHSA-jf5r-wgf4-qhxf | Exploit Vendor Advisory |
| https://github.com/cxong/tinydir/releases/tag/1.2.6 | Release Notes |
| http://www.openwall.com/lists/oss-security/2023/12/04/1 | Mailing List Third Party Advisory |
| http://packetstormsecurity.com/files/176060/TinyDir-1.2.5-Buffer-Overflow.html | Exploit Third Party Advisory VDB Entry |
| http://seclists.org/fulldisclosure/2023/Dec/14 |
Configurations
Information
Published : 2023-12-04 06:15
Updated : 2023-12-13 03:15
NVD link : CVE-2023-49287
Mitre link : CVE-2023-49287
JSON object : View
Products Affected
cxong
- tinydir
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
