CVE Vulnerabilities

CVE-2023-26266

Published: Feb 21, 2023 | Modified: Mar 14, 2025
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.

Affected Software

NameVendorStart VersionEnd Version
Afl++Afl++_project4.05c (including)4.05c (including)
AflplusplusUbuntufocal*
AflplusplusUbuntukinetic*
AflplusplusUbuntulunar*
AflplusplusUbuntumantic*
AflplusplusUbuntuoracular*
AflplusplusUbuntuplucky*
AflplusplusUbuntutrusty*
AflplusplusUbuntuxenial*

References