CVE-2019-17264

LOW

libyal liblnk <20191006 - Buffer Overflow

Title source: llm

Description

In libyal liblnk before 20191006, liblnk_location_information_read_data in liblnk_location_information.c has a heap-based buffer over-read because an incorrect variable name is used for a certain offset. NOTE: the vendor has disputed this as described in the GitHub issue

Scores

CVSS v3 3.3
EPSS 0.0013
EPSS Percentile 32.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Classification

CWE
CWE-125 CWE-682
Status published

Affected Products (1)

liblnk_project/liblnk < 20191006

Timeline

Published Oct 06, 2019
Tracked Since Feb 18, 2026