Description
Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.
References (2)
Core 2
Core References
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://huntr.dev/bounties/9a90ffa1-38f5-4685-9c00-68ba9068ce3d
Patch, Third Party Advisory x_refsource_misc
https://github.com/bfabiszewski/libmobi/commit/fb1ab50e448ddbed746fd27ae07469bc506d838b
Scores
CVSS v3
7.1
EPSS
0.0013
EPSS Percentile
31.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Details
CWE
CWE-125
CWE-126
Status
published
Products (1)
libmobi_project/libmobi
< 0.11
Published
Apr 29, 2022
Tracked Since
Feb 18, 2026