pl: code execution
Package(s): | pl | CVE #(s): | CVE-2012-6090 CVE-2012-6089 | ||||||||||||||||
Created: | January 15, 2013 | Updated: | December 6, 2013 | ||||||||||||||||
Description: | From the CVE entries:
Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename. (CVE-2012-6090) Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename. (CVE-2012-6089) | ||||||||||||||||||
Alerts: |
|