CVE-2021-36089: Buffer Overflow
Published Jul 1, 2021
·Updated
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::applypaletteclr (called from grk::FileFormatDecompress::applyColour).
Affected Software
2 affected components
Zope Grok>=7.6.6<=9.2.0
Linux Linux kernel
Remediation
Patch Available
Event History
Jul 1, 2021
CVE Published
via MITRE·02:50 AM
Data Sourced
via MITRE·02:50 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-36089.
2
What is the severity of CVE-2021-36089?
The severity of CVE-2021-36089 is high, with a severity value of 7.8.
3
Which software versions are affected by CVE-2021-36089?
Grok versions 7.6.6 through 9.2.0 are affected by CVE-2021-36089.
4
What is the CWE ID of CVE-2021-36089?
The CWE ID of CVE-2021-36089 is CWE-119 and CWE-787.
5
How can I fix CVE-2021-36089?
To fix CVE-2021-36089, update your Grok software to a version higher than 9.2.0.