CVE-2018-17942

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
gnugnulib
𝑥
< 2018-09-23
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gnulib
bullseye
20210102~ebaa53c-1
fixed
bookworm
20230209+stable-1
fixed
sid
20240701-1
fixed
trixie
20240701-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnulib
disco
not-affected
cosmic
Fixed 20140202+stable-3.1~build0.18.10.1
released
bionic
Fixed 20140202stable-2deb8u1build0.18.04.1
released
xenial
Fixed 20140202stable-2deb8u1build0.16.04.1
released
trusty
dne