CVE-2021-3548

HIGH

dmg2img <20170502 - Info Disclosure

Title source: llm
STIX 2.1

Description

A flaw was found in dmg2img through 20170502. dmg2img did not validate the size of the read buffer during memcpy() inside the main() function. This possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.

References (1)

Core 1
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1959585

Scores

CVSS v3 7.1
EPSS 0.0029
EPSS Percentile 52.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Details

CWE
CWE-125
Status published
Products (1)
dmg2img_project/dmg2img < 20170502
Published May 26, 2021
Tracked Since Feb 18, 2026