Skip to content
Noroxi

pkgconf records

2 published records for vendor pkgconf.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 23

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

2 records
  • pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte al

    CriticalCVSS 9.8No exploitEPSS 1%

    pkgconf · pkgconfAug 20, 2018

  • In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tu

    MediumCVSS 5.5No exploitEPSS 1%

    pkgconf · pkgconfJan 22, 2023