CVE-2018-12096

MEDIUM

liblnk <2018-04-19 - Info Disclosure

Title source: llm
STIX 2.1

Description

The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub

References (1)

Core 1
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Jun/33

Scores

CVSS v3 5.5
EPSS 0.0010
EPSS Percentile 27.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (1)
liblnk_project/liblnk < 20180419
Published Jun 19, 2018
Tracked Since Feb 18, 2026