CVE-2018-12098

MEDIUM

liblnk <2018-04-19 - Info Disclosure

Title source: llm
STIX 2.1

Description

The liblnk_data_block_read function in liblnk_data_block.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub

References (1)

Core 1
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Jun/33

Scores

CVSS v3 5.5
EPSS 0.0026
EPSS Percentile 49.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-125 CWE-200
Status published
Products (1)
liblnk_project/liblnk < 20180419
Published Jun 19, 2018
Tracked Since Feb 18, 2026