CVE-2021-30184 is a high-severity buffer overflow vulnerability in GNU Chess 6.2.7, allowing arbitrary code execution through specially crafted Portable Game Notation (PGN) data. This flaw affects GNU Chess and related Fedora Project distributions. The attack requires user interaction (UI:R) to load a malicious PGN file, but once triggered, it can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Currently, there is no public exploit code available, and the vulnerability shows minimal community discussion or media coverage, indicating a low level of active exploitation or widespread awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.2.7CPE matchmatch criteria | cpe:2.3:a:gnu:chess:6.2.7:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.