Input validation error in Chicken Scheme - CVE-2012-6123

 

Input validation error in Chicken Scheme - CVE-2012-6123

Published: October 31, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35125
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-6123
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."


Affected software

Chicken Scheme

How to mitigate CVE-2012-6123

Install update from vendor's website.

Chicken Scheme - update to 4.8.0

External References

Related Security Bulletins