flex.skl in Will Estes and John Millaway Fast Lexical Analyzer...
Vulnerability Description
flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-0459
Credits & Attribution
No credits recorded in the NVD database.
References
- http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download
- http://www.osvdb.org/23440
- http://www.us.debian.org/security/2006/dsa-1020
- http://www.vupen.com/english/advisories/2006/0770
- http://secunia.com/advisories/19071
- http://www.securityfocus.com/bid/16896
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24995
- http://www.gentoo.org/security/en/glsa/glsa-200603-07.xml
- http://secunia.com/advisories/19228
- http://secunia.com/advisories/19424
- http://securityreason.com/securityalert/570
- http://secunia.com/advisories/19126
- https://usn.ubuntu.com/260-1/
- http://sourceforge.net/mailarchive/forum.php?thread_name=20060223020346.GA11231%40tabitha.home.tldz.org&forum_name=flex-announce
Affected Vendor
westes
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.