#VU35127 Input validation error in Chicken Scheme - CVE-2012-6125
Published: October 31, 2019 / Updated: August 8, 2020
Vulnerability identifier: #VU35127
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2012-6125
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Chicken Scheme
Chicken Scheme
Software vendor:
call-cc.org
call-cc.org
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
Remediation
Install update from vendor's website.
External links
- http://www.openwall.com/lists/oss-security/2013/02/08/2
- https://access.redhat.com/security/cve/cve-2012-6125
- https://lists.nongnu.org/archive/html/chicken-hackers/2012-01/msg00002.html
- https://lists.nongnu.org/archive/html/chicken-hackers/2012-01/msg00020.html
- https://security-tracker.debian.org/tracker/CVE-2012-6125