CVE-2012-6122

HIGH

Call-cc Chicken < 4.8.0.1 - Buffer Overflow

Title source: rule
STIX 2.1

Description

Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.

References (8)

Core 8
Core References
Third Party Advisory x_refsource_misc
https://security-tracker.debian.org/tracker/CVE-2012-6122
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2013/02/08/2
Mailing List, Patch, Release Notes, Third Party Advisory x_refsource_misc
http://lists.gnu.org/archive/html/chicken-announce/2013-10/msg00000.html
Mailing List, Patch, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2013/05/08/3
Mailing List, Patch, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2013/05/09/1
Mailing List, Third Party Advisory x_refsource_confirm
https://lists.nongnu.org/archive/html/chicken-users/2012-06/msg00031.html
Mailing List, Patch, Third Party Advisory x_refsource_confirm
https://lists.nongnu.org/archive/html/chicken-hackers/2012-11/msg00075.html

Scores

CVSS v3 7.5
EPSS 0.0180
EPSS Percentile 82.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-120
Status published
Products (1)
call-cc/chicken < 4.8.0.1
Published Oct 31, 2019
Tracked Since Feb 18, 2026