CVE-2012-6090
EPSS 3.1%
Description
Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.
How to fix CVE-2012-6090
To remediate CVE-2012-6090, upgrade the affected package to a fixed version below.
- Debian/swi-prolog—upgrade to 5.10.4-5 or later
Is CVE-2012-6090 being exploited?
Low — EPSS is 3.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 5.10.4-5