6.8
CVSSv2

CVE-2011-3631

Published: 26/11/2019 Updated: 18/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Hardlink prior to 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hardlink project hardlink

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

redhat enterprise linux 5.0

redhat enterprise linux 6.0