Loading product vulnerabilities…
Total
2
Critical
0
High
0
Medium
0
CISA KEV
0
Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hijack of the process running with administrative privileges triggered by specially crafted input string.
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.