Input validation error in Chicken Scheme - CVE-2012-6123
Published: October 31, 2019 / Updated: August 8, 2020
Vulnerability identifier: #VU35125
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-6123
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
Affected software
Chicken Scheme
How to mitigate CVE-2012-6123
Install update from vendor's website.
Chicken Scheme - update to 4.8.0