CVE-2023-46586

EUVD-2023-50790
cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strncpy is misused.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
weborf_projectweborf
𝑥
< 1.0
ADP
Debian logo
Debian Releases
Debian Product
Codename
weborf
bookworm
0.19-2.1+deb12u1
fixed
bullseye
0.17-3+deb11u1
fixed
buster
not-affected
sid
1.4-1
fixed
trixie
1.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
weborf
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
lunar
ignored
mantic
ignored
noble
needs-triage
oracular
not-affected
trusty
ignored
xenial
needs-triage