First published: Thu Jul 01 2021(Updated: )
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zope Grok | >=7.6.6<=9.2.0 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36089.
The severity of CVE-2021-36089 is high, with a severity value of 7.8.
Grok versions 7.6.6 through 9.2.0 are affected by CVE-2021-36089.
The CWE ID of CVE-2021-36089 is CWE-119 and CWE-787.
To fix CVE-2021-36089, update your Grok software to a version higher than 9.2.0.