An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/TeamSeri0us/pocs/tree/master/recutils/bug-report-recutils/rec2csv | third party advisory |
https://github.com/TeamSeri0us/pocs/blob/master/recutils/bug-report-recutils | third party advisory exploit |