Heap-based Buffer Over-read in Libmobi 0.3's mobi_parse_index_entry Function

Heap-based Buffer Over-read in Libmobi 0.3's mobi_parse_index_entry Function

CVE-2018-11725 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:N/A:N

The mobi_parse_index_entry function in index.c in Libmobi 0.3 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted mobi file.

Learn more about our Cis Benchmark Audit For Ibm I.