In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/AFLplusplus/AFLplusplus/pull/1643 |
|
History
Fri, 14 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-427 | |
| Metrics |
ssvc
|
Tue, 27 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2023-02-21T00:00:00.000Z
Updated: 2025-03-14T18:24:00.238Z
Reserved: 2023-02-21T00:00:00.000Z
Link: CVE-2023-26266
Updated: 2024-08-02T11:46:23.431Z
Status : Modified
Published: 2023-02-21T04:15:10.693
Modified: 2025-03-14T19:15:42.750
Link: CVE-2023-26266
No data.