CVE-2023-33552

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 1, 2023
Updated: Jan 9, 2025
CWE ID 787

Summary

CVE-2023-33552 is a critical vulnerability affecting the erofs-utils v1.6 software. This issue involves a heap buffer overflow in the erofs_read_one_data function located at data.c. An attacker can exploit this flaw by crafting a malicious erofs filesystem image, leading to arbitrary code execution. Successful exploitation grants the attacker significant control over the affected system. This vulnerability poses a serious risk and requires immediate attention from users of erofs-utils v1.6. It is essential to update to the latest version or apply relevant patches as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share