A flaw has been found in GNU Bison up to 3.8.2. This affects the function __obstack_vprintf_internal of the file obprintf.c. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been published and may be used. It is still unclear if this vulnerability genuinely exists. The issue could not be reproduced from a GNU Bison 3.8.2 tarball run in a Fedora 42 container.
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Link | Tags |
---|---|
https://vuldb.com/?id.319229 | vdb entry technical description |
https://vuldb.com/?ctiid.319229 | permissions required signature |
https://vuldb.com/?submit.622298 | third party advisory |
https://vuldb.com/?submit.622299 | third party advisory |
https://github.com/akimd/bison/issues/113 | issue tracking |
https://github.com/akimd/bison/issues/114 | issue tracking exploit |
https://www.gnu.org/ | product |