CVE-2021-46022
published 2022-01-14CVE-2021-46022: An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
PriorityP416medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.97%
57.9th percentile
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | recutils | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | recutils | — | — |
| gnu | recutils | >= 0 < 1.7-1ubuntu0.1~esm1 | 1.7-1ubuntu0.1~esm1 |
| gnu | recutils | >= 0 < 1.7-2ubuntu0.1~esm1 | 1.7-2ubuntu0.1~esm1 |
| gnu | recutils | >= 0 < 1.8-1ubuntu0.20.04.1~esm1 | 1.8-1ubuntu0.20.04.1~esm1 |
| gnu | recutils | >= 0 < 1.8-1ubuntu0.22.04.1~esm1 | 1.8-1ubuntu0.22.04.1~esm1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
recutils vulnerabilities
osv·2024-12-04·CVSS 6.5
CVE-2021-46019 [MEDIUM] recutils vulnerabilities
recutils vulnerabilities
It was discovered that recutils incorrectly handled memory when parsing
comments with the recparser utility. An attacker could possibly use this
issue to cause a denial of service or run arbitrary commands.
(CVE-2021-46019, CVE-2021-46021, CVE-2021-46022)
It was discovered that recutils incorrectly handled memory when parsing CSV
files. An attacker could possibly use this issue to cause a denial of
service or run arbitrary commands. (CVE-2019-11637, CVE-2019-11638,
CVE-2019-11639, CVE-2019-11640)
It was discovered that recutils incorrectly handled memory when parsing
maliciously crafted recfiles. An attacker could possibly use this issue to
cause a denial of service. (CVE-2019-6455, CVE-2019-6456, CVE-2019-6457,
CVE-2019-6458, CVE-2019-6459, CVE-2019-6460)
GHSA
GHSA-5m66-q83m-q8c2: An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset
ghsa_unreviewed·2022-01-15
CVE-2021-46022 [MEDIUM] CWE-416 GHSA-5m66-q83m-q8c2: An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
OSV
CVE-2021-46022: An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset
osv·2022-01-14·CVSS 5.5
CVE-2021-46022 [MEDIUM] CVE-2021-46022: An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
Ubuntu
recutils vulnerabilities
vendor_ubuntu·2024-12-04·CVSS 6.5
CVE-2021-46021 [MEDIUM] recutils vulnerabilities
Title: recutils vulnerabilities
Summary: recutils could be made to crash or run programs as a login user if a
specially crafted file was opened.
It was discovered that recutils incorrectly handled memory when parsing
comments with the recparser utility. An attacker could possibly use this
issue to cause a denial of service or run arbitrary commands.
(CVE-2021-46019, CVE-2021-46021, CVE-2021-46022)
It was discovered that recutils incorrectly handled memory when parsing CSV
files. An attacker could possibly use this issue to cause a denial of
service or run arbitrary commands. (CVE-2019-11637, CVE-2019-11638,
CVE-2019-11639, CVE-2019-11640)
It was discovered that recutils incorrectly handled memory when parsing
maliciously crafted recfiles. An attacker could possibly use this issue to
ca
Debian
CVE-2021-46022: recutils - An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU ...
vendor_debian·2021·CVSS 5.5
CVE-2021-46022 [MEDIUM] CVE-2021-46022: recutils - An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU ...
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/gnu-mirror-unofficial/recutils/commit/34b75ed7ad492c8e38b669ebafe0176f1f9992d2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDVOFC3HTBG7DF2PZTEXRMG4CV2F55UF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VRSXSN2XF6PX74WDYVV26TQMYIFAEQ3T/https://lists.gnu.org/archive/html/bug-recutils/2021-12/msg00007.htmlhttps://nvd.nist.gov/vuln/detail/CVE-2021-46022https://github.com/gnu-mirror-unofficial/recutils/commit/34b75ed7ad492c8e38b669ebafe0176f1f9992d2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDVOFC3HTBG7DF2PZTEXRMG4CV2F55UF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VRSXSN2XF6PX74WDYVV26TQMYIFAEQ3T/https://lists.gnu.org/archive/html/bug-recutils/2021-12/msg00007.htmlhttps://nvd.nist.gov/vuln/detail/CVE-2021-46022
2022-01-14
Published