CVE-2012-6089
EPSS 4.0%
Description
Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.
How to fix CVE-2012-6089
To remediate CVE-2012-6089, upgrade the affected package to a fixed version below.
- Debian/swi-prolog—upgrade to 5.10.4-5 or later
Is CVE-2012-6089 being exploited?
Low — EPSS is 4.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 5.10.4-5