Description
TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.
References (5)
Core 5
Core References
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/176060/TinyDir-1.2.5-Buffer-Overflow.html
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/12/04/1
Mailing List
http://seclists.org/fulldisclosure/2023/Dec/14
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/cxong/tinydir/security/advisories/GHSA-jf5r-wgf4-qhxf
Release Notes x_refsource_misc
https://github.com/cxong/tinydir/releases/tag/1.2.6
Scores
CVSS v3
7.7
EPSS
0.0249
EPSS Percentile
85.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-121
CWE-120
Status
published
Products (1)
cxong/tinydir
< 1.2.6
Published
Dec 04, 2023
Tracked Since
Feb 18, 2026