VDB

CVE-2021-42341

CVE-2021-42341 PUBLISHED CVSS 7.5 HIGH

checkpath in OpenRC before 0.44.7 uses the direct output of strlen() to allocate strings, which does not account for the '\0' byte at the end of the string. This results in memory corruption. CVE-2021-42341 was introduced in git commit 63db2d99e730547339d1bdd28e8437999c380cae, which was introduced as part of OpenRC 0.44.0 development.

EPSS 2.12% · 80.5th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
2.12%
80.5th percentile

Affected Products

VendorProductVersions
n/an/an/a
openrc_projectopenrc0.44.0

Timeline

  • Oct 14, 2021 EPSS Score
  • Oct 14, 2021 CVE Published
  • Dec 10, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 2, 2022 EPSS Score
  • May 28, 2022 EPSS Score
  • Jul 25, 2022 EPSS Score
  • Sep 20, 2022 EPSS Score
  • Nov 15, 2022 EPSS Score
  • Jan 11, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›