Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "6.6.4-2ubuntu1", "binary_name": "swi-prolog" }, { "binary_version": "6.6.4-2ubuntu1", "binary_name": "swi-prolog-java" }, { "binary_version": "6.6.4-2ubuntu1", "binary_name": "swi-prolog-nox" }, { "binary_version": "6.6.4-2ubuntu1", "binary_name": "swi-prolog-odbc" }, { "binary_version": "6.6.4-2ubuntu1", "binary_name": "swi-prolog-x" } ] }