CVE-2006-0459
Last modified
CVE-2006-0459 is a vulnerability of currently unknown severity. flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.. EPSS estimates a 4.77% chance of exploitation in the next 30 days.
Description
flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Westes | Flex | <= 2.5.32 |
References
- http://secunia.com/advisories/19071Patch, Vendor Advisory
- http://secunia.com/advisories/19126Vendor Advisory
- http://secunia.com/advisories/19228Vendor Advisory
- http://secunia.com/advisories/19424Patch, Vendor Advisory
- http://securityreason.com/securityalert/570Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200603-07.xmlThird Party Advisory
- http://www.osvdb.org/23440Broken Link, Patch
- http://www.securityfocus.com/bid/16896Patch, Third Party Advisory, VDB Entry
- http://www.us.debian.org/security/2006/dsa-1020Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0770Broken Link, URL Repurposed
- https://usn.ubuntu.com/260-1/Third Party Advisory
- http://secunia.com/advisories/19071Patch, Vendor Advisory
- http://secunia.com/advisories/19126Vendor Advisory
- http://secunia.com/advisories/19228Vendor Advisory
- http://secunia.com/advisories/19424Patch, Vendor Advisory
- http://securityreason.com/securityalert/570Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200603-07.xmlThird Party Advisory
- http://www.osvdb.org/23440Broken Link, Patch
- http://www.securityfocus.com/bid/16896Patch, Third Party Advisory, VDB Entry
- http://www.us.debian.org/security/2006/dsa-1020Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0770Broken Link, URL Repurposed
- https://usn.ubuntu.com/260-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0459?
How severe is CVE-2006-0459?
How do I fix CVE-2006-0459?
Are you affected by CVE-2006-0459?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
