CVE Vulnerabilities

CVE-2023-26266

Published: Feb 21, 2023 | Modified: Aug 27, 2024
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.

Affected Software

Name Vendor Start Version End Version
Afl++ Afl++_project 4.05c (including) 4.05c (including)
Aflplusplus Ubuntu kinetic *
Aflplusplus Ubuntu lunar *
Aflplusplus Ubuntu mantic *
Aflplusplus Ubuntu trusty *
Aflplusplus Ubuntu xenial *

References