CVE-2019-5038
Description
An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in code execution. An attacker can trigger this vulnerability by convincing the user to open a specially crafted Weave command.
CWE
- CWE-121 — CWE-121: Stack-based Buffer Overflow
Affected
- n/a / Nest Labs — v=Nest Labs Openweave-core 4.0.2 [affected]
CVSS
- 3.0 score=7.5 severity=HIGH
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0801 x_refsource_MISC
Source
cvelistV5-main/cves/2019/5xxx/CVE-2019-5038.json