GHSA-377p-g8gr-5wpgLowCVSS 3.9
LIEF obtain sensitive information via the name parameter
🔗 CVE IDs covered (1)
📋 Description
An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.
🎯 Affected products1
- pip/lief:< 0.15.0
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2024-31636
- https://github.com/lief-project/LIEF/issues/1038
- https://github.com/lief-project/LIEF
- https://github.com/lief-project/LIEF/commit/307e113f8e00b034f0a5f1baa33e54d636c52ea3
- https://github.com/pypa/advisory-database/tree/main/vulns/lief/PYSEC-2024-280.yaml
- http://lief.com
- https://github.com/advisories/GHSA-377p-g8gr-5wpg