CVE-2025-8733 Information

Description

A vulnerability was found in GNU Bison up to 3.8.2. It has been rated as problematic. This issue affects the function __obstack_vprintf_internal of the file obprintf.c. The manipulation leads to reachable assertion. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Reference

https://github.com/akimd/bison/issues/113 https://github.com/akimd/bison/issues/114 https://vuldb.com/?ctiid.319229 https://vuldb.com/?id.319229 https://vuldb.com/?submit.622298 https://vuldb.com/?submit.622299 https://www.gnu.org/

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

LOW

Base Severity

3.3

CNNVD-202508-768 (Published: 2025-08-08)

Share on: