Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | N/A |
CWE-ID | CWE-125 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Mastodon Server applications / Other server solutions |
Vendor | Mastodon |
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU69421
Risk: Medium
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in blurhash transcoder. A remote attacker can trigger out-of-bounds read error and read contents of memory on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsMastodon: 3.4.0 - 3.5.3
http://github.com/mastodon/mastodon/releases/tag/v4.0.0
http://github.com/mastodon/mastodon/releases/tag/v3.4.9
http://github.com/mastodon/mastodon/releases/tag/v3.5.4
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?