CVE Vulnerabilities

CVE-2023-33461

NULL Pointer Dereference

Published: Jun 01, 2023 | Modified: Jan 09, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for function iniparser_getstrings return.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
IniparserNdevilla4.1 (including)4.1 (including)
IniparserUbuntubionic*
IniparserUbuntuesm-apps/bionic*
IniparserUbuntuesm-apps/focal*
IniparserUbuntufocal*
IniparserUbuntujammy*
IniparserUbuntukinetic*
IniparserUbuntulunar*
IniparserUbuntumantic*
IniparserUbuntutrusty*
IniparserUbuntuxenial*

Potential Mitigations

References