CVE-2012-2677

Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large memory chunk size value, which causes less memory to be allocated than expected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
boostpool
𝑥
≤ 1.0.0
boostpool
2.0.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
boost
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hardy
ignored
hirsute
dne
lucid
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
boost1.40
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hardy
dne
hirsute
dne
lucid
ignored
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
boost1.42
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hardy
dne
hirsute
dne
lucid
dne
natty
ignored
oneiric
ignored
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
boost1.46
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hardy
dne
hirsute
dne
lucid
dne
natty
dne
oneiric
ignored
precise
ignored
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
boost1.48
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hardy
dne
hirsute
dne
lucid
dne
natty
dne
oneiric
dne
precise
ignored
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
boost1.49
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hardy
dne
hirsute
dne
lucid
dne
natty
dne
oneiric
dne
precise
dne
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
boost1.50
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hardy
dne
hirsute
dne
lucid
dne
natty
dne
oneiric
dne
precise
dne
quantal
ignored
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
boost
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-date-time
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-devel
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-doc
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-filesystem
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-graph
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-graph-mpich2
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-graph-openmpi
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-iostreams
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-math
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-mpich2
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-mpich2-devel
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-mpich2-python
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-openmpi
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-openmpi-devel
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-openmpi-python
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-program-options
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-python
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-regex
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-serialization
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-signals
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-static
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-system
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-test
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-thread
RHEL 6
0:1.41.0-15.el6_4
fixed
boost-wave
RHEL 6
0:1.41.0-15.el6_4
fixed
Common Weakness Enumeration