CVE-2023-46049
MEDIUMLLVM 15.0.0 - NULL Pointer Dereference in parseOneMetadata()
Title source: llmDescription
LLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a crafted .o file) to llvm-lto. NOTE: this is disputed because the relationship between pdflatex.fmt and any LLVM language front end is not explained, and because a crash of the llvm-lto application should be categorized as a usability problem.
References (4)
Core 4
Core References
Various Sources
https://llvm.org/docs/Security.html
Issue Tracking
https://github.com/llvm/llvm-project/issues/67388
Mailing List
http://seclists.org/fulldisclosure/2024/Jan/66
Exploit, Third Party Advisory
http://packetstormsecurity.com/files/176820/llvm-LLVM-15-Null-Pointer.html
Scores
CVSS v3
5.3
EPSS
0.0068
EPSS Percentile
47.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Published
Mar 27, 2024
Tracked Since
Feb 18, 2026