CVE-2021-32297 – lief
Package
Manager: pip
Name: lief
Vulnerable Version: >=0 <0.11.0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00554 pctl0.67089
Details
LIEF heap-buffer-overflow An issue was discovered in LIEF prior to version 0.11.0. A heap-buffer-overflow exists in the function main located in `pe_reader.c`. It allows an attacker to cause code Execution.
Metadata
Created: 2022-05-24T19:15:12Z
Modified: 2024-09-30T16:43:57Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-22x7-vwh9-5w4g/GHSA-22x7-vwh9-5w4g.json
CWE IDs: ["CWE-787"]
Alternative ID: GHSA-22x7-vwh9-5w4g
Finding: F111
Auto approve: 1