Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The C function ei_s_print_term uses an internal 2000-character stack buffer to format terms. When called with an encoded Erlang term containing a very large integer (encoded representation exceeding 2000 characters), the buffer overflows. The overflow bytes are restricted to the ASCII values of 0-9 and A-F, which limits exploitation to Denial of Service. The companion function ei_print_term, which prints directly to a FILE instead of a memory buffer, does not contain this bug. This issue affects OTP from OTP 17.0 before OTP 29.0.2, OTP 28.5.0.2 and OTP 27.3.4.13, corresponding to erl_interface from 3.7.16 before 5.8.1, 5.7.0.1 and 5.5.2.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.7.16, < 5.5.2.1CPE matchmatch criteria | cpe:2.3:a:erlang:erl_interface:*:*:*:*:*:*:*:* | ||
>= 5.7, < 5.7.0.1CPE matchmatch criteria | cpe:2.3:a:erlang:erl_interface:*:*:*:*:*:*:*:* | ||
>= 5.8, < 5.8.1CPE matchmatch criteria | cpe:2.3:a:erlang:erl_interface:*:*:*:*:*:*:*:* | ||
>= 17.0, < 27.3.4.13CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | ||
>= 28.0, < 28.5.0.2CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.