libyal/liblnk

libyal/liblnk

Releases8
Frequency6 months 4 days
Last Release
Stars216
Library and tools to access the Windows Shortcut File (LNK) format

CVE History

CVEPublishedCVSS v3CVSS v2
3.3 LOW2.1 LOW

libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_location_information_read_data in liblnk_location_information.c, a different issue than CVE-2019-17264. NOTE: the vendor has disputed this as described in the GitHub issue

3.3 LOW2.1 LOW

In libyal liblnk before 20191006, liblnk_location_information_read_data in liblnk_location_information.c has a heap-based buffer over-read because an incorrect variable name is used for a certain offset. NOTE: the vendor has disputed this as described in the GitHub issue