Candidate: CVE-2011-3631 PublicDate: 2019-11-26 04:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3631 Description: Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges. Ubuntu-Description: Notes: tyhicks> This is for the C version of hardlink Bugs: http://security-tracker.debian.org/tracker/CVE-2011-3631 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_hardlink: upstream_hardlink: not-affected hardy_hardlink: DNE lucid_hardlink: not-affected (Python version not affected) maverick_hardlink: not-affected (Python version not affected) natty_hardlink: not-affected (Python version not affected) oneiric_hardlink: not-affected (Python version not affected) devel_hardlink: not-affected (Python version not affected)