A vulnerability has been found in Tarantool up to 3.3.1 and classified as problematic. Affected by this vulnerability is the function tm_to_datetime in the library src/lib/core/datetime.c. The manipulation leads to reachable assertion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Link | Tags |
---|---|
https://vuldb.com/?id.313663 | technical description vdb entry |
https://vuldb.com/?ctiid.313663 | permissions required signature |
https://vuldb.com/?submit.597454 | third party advisory |
https://github.com/tarantool/tarantool/issues/11347 | issue tracking |
https://github.com/user-attachments/files/19613858/tarantool_crash.txt | exploit |