CVE-2022-26507

Severity
9.8CRITICAL
EPSS
6.7%
top 8.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateApr 15

Description

A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-92r8-w862-f2pj: ** UNSUPPORTED WHEN ASSIGNED ** A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 02022-04-15
CVEList
CVE-2022-26507: A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 02022-04-14
CVE-2022-26507 (CRITICAL CVSS 9.8) | A heap-based buffer overflow exists | cvebase.io