news.mlab.sh
Back to the feed
vulnerability

CISA Malcolm

High
Summary

Several vulnerabilities in CISA Malcolm allow for denial-of-service attacks and arbitrary code execution. Versions prior to 26.06.1 and 26.07.1 are affected. The vulnerabilities stem from issues related to unbounded file extraction, improper authorization checks, and compressed data handling, leading to potential resource exhaustion and remote code execution. The CISA has released patches to address these issues.

Read the full article at CISA Advisories

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.