CVE-2023-26266

In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:afl\+\+_project:afl\+\+:4.05c:*:*:*:*:*:*:*

History

27 Aug 2024, 19:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.3

Information

Published : 2023-02-21 04:15

Updated : 2024-08-27 19:40


NVD link : CVE-2023-26266

Mitre link : CVE-2023-26266

CVE.ORG link : CVE-2023-26266


JSON object : View

Products Affected

afl\+\+_project

  • afl\+\+