CVE-2023-46046

An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is no common libminizinc use case in which an unattended process is supposed to run forever to process a series of atttacker-controlled .mzn files.
Configurations

No configuration.

History

21 Nov 2024, 08:27

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/Jan/63 - () http://seclists.org/fulldisclosure/2024/Jan/63 -
References () https://github.com/MiniZinc/libminizinc/commit/afe67acc20898e4308044b54c4acf7a08df544f0 - () https://github.com/MiniZinc/libminizinc/commit/afe67acc20898e4308044b54c4acf7a08df544f0 -
References () https://github.com/MiniZinc/libminizinc/issues/730 - () https://github.com/MiniZinc/libminizinc/issues/730 -
References () https://www.minizinc.org/doc-2.8.3/en/changelog.html - () https://www.minizinc.org/doc-2.8.3/en/changelog.html -

05 Nov 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-476

27 Mar 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-27 05:15

Updated : 2024-11-21 08:27


NVD link : CVE-2023-46046

Mitre link : CVE-2023-46046

CVE.ORG link : CVE-2023-46046


JSON object : View

Products Affected

No product.

CWE
CWE-476

NULL Pointer Dereference