cbcvebase.

Gnu Libcdio vulnerabilities

6 known vulnerabilities affecting gnu/libcdio.

Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2007-6613P4MEDIUMCVSS 5.0PoC≤ 0.792008-01-03
CVE-2007-6613 [MEDIUM] CWE-119 CVE-2007-6613: Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GN Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio) 0.79 and earlier allows context-dependent attackers to cause a denial of service (core dump) and possibly execute arbitrary code via a disk or image that contains a long joilet file name.
nvdosv
CVE-2017-18201P3CRITICALCVSS 9.8fixed in 2.0.02018-02-26
CVE-2017-18201 [CRITICAL] CWE-415 CVE-2017-18201: An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
nvdosv
CVE-2017-18198P3HIGHCVSS 8.8fixed in 1.0.02018-02-24
CVE-2017-18198 [HIGH] CWE-125 CVE-2017-18198: print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a d print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted iso file.
nvdosv
CVE-2024-36600P3HIGHCVSS 8.4≥ 2.2.0, < 2.3.02024-06-14
CVE-2024-36600 [HIGH] CWE-121 CVE-2024-36600: Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitr Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
nvd
CVE-2017-18199P4MEDIUMCVSS 6.5fixed in 1.0.02018-02-24
CVE-2017-18199 [MEDIUM] CWE-476 CVE-2017-18199: realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of s realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted iso file.
nvdosv
CVE-2004-1476P4MEDIUMCVSS 5.1≥ 0, < 0.692004-12-31
CVE-2004-1476 [MEDIUM] CVE-2004-1476: Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label.
osv
Gnu Libcdio vulnerabilities | cvebase