Skip to content

[GHSA-r98r-j25q-rmpr] Type confusion in failure#392

Closed
Noratrieb wants to merge 1 commit into
Nilstrieb/advisory-improvement-392from
Nilstrieb-GHSA-r98r-j25q-rmpr
Closed

[GHSA-r98r-j25q-rmpr] Type confusion in failure#392
Noratrieb wants to merge 1 commit into
Nilstrieb/advisory-improvement-392from
Nilstrieb-GHSA-r98r-j25q-rmpr

Conversation

@Noratrieb
Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS
  • Severity

@github-actions github-actions Bot changed the base branch from main to Nilstrieb/advisory-improvement-392 June 11, 2022 17:05
@Noratrieb
Copy link
Copy Markdown
Author

The developer would have to overwrite this function on purpose. If a malicious developer overwrite this function on purpose in their own application or library, they would be able to cause memory corruption in safe code. Note that this requires full access to the source code or build step, and is therefore an impractical attack vector.
If full access to the source code or build step was obtained, it would be trivial to cause way worse problems by changing the application code in other ways unrelated to this advistory.

@shelbyc
Copy link
Copy Markdown
Contributor

shelbyc commented Jun 17, 2022

If you want to contest information from the CVE, please contact the issuer, MITRE.

@github-actions github-actions Bot deleted the Nilstrieb-GHSA-r98r-j25q-rmpr branch June 17, 2022 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants