Vulnerability Details CVE-2015-4646
(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2015-4646
-
cpe:2.3:a:squashfs_project:squashfs:1.3
-
cpe:2.3:a:squashfs_project:squashfs:2.0
-
cpe:2.3:a:squashfs_project:squashfs:2.1
-
cpe:2.3:a:squashfs_project:squashfs:2.2
-
cpe:2.3:a:squashfs_project:squashfs:3.0
-
cpe:2.3:a:squashfs_project:squashfs:3.1
-
cpe:2.3:a:squashfs_project:squashfs:3.2
-
cpe:2.3:a:squashfs_project:squashfs:3.3
-
cpe:2.3:a:squashfs_project:squashfs:3.4
-
cpe:2.3:a:squashfs_project:squashfs:4.0
-
cpe:2.3:a:squashfs_project:squashfs:4.1
-
cpe:2.3:a:squashfs_project:squashfs:4.2
-
cpe:2.3:a:squashfs_project:squashfs:4.3