Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-46046

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MiniZinc是一种高级约束建模语言,用于轻松表达和解决离散优化问题。 MiniZinc 2.8.0之前版本存在安全漏洞,该漏洞源于允许通过特制的 .mzn 文件中的 ti_expr 进行 NULL 指针取消引用。

AI Predicted 5.5 Difficulty: Easy EPSS 0.28% · P21

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-46046

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is no common libminizinc use case in which an unattended process is supposed to run forever to process a series of atttacker-controlled .mzn files.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
MiniZinc 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
MiniZinc是一种高级约束建模语言,用于轻松表达和解决离散优化问题。 MiniZinc 2.8.0之前版本存在安全漏洞,该漏洞源于允许通过特制的 .mzn 文件中的 ti_expr 进行 NULL 指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2023-46046

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-46046

登录查看更多情报信息。

Patches & Fixes for CVE-2023-46046 (1)

Mailing List Discussions for CVE-2023-46046 (1)

Other References for CVE-2023-46046 (2)

Same Patch Batch · n/a · 2024-03-27 · 48 CVEs total

CVE-2023-46048 Tex Live 安全漏洞
CVE-2023-31634 TeslaMate 安全漏洞
CVE-2023-46049 LLVM 安全漏洞
CVE-2023-43768 Couchbase Server 安全漏洞
CVE-2024-28815 Mitel InAttend 安全漏洞
CVE-2024-28085 util-linux 安全漏洞
CVE-2023-47438 Reportico 安全漏洞
CVE-2024-25354 domain-suffix 安全漏洞
CVE-2024-28335 Lektor 代码问题漏洞
CVE-2023-25364 Opswat Metadefender Core 安全漏洞
CVE-2023-29134 MediaWiki 安全漏洞
CVE-2023-46047 SANE Backends 安全漏洞
CVE-2023-45925 GNU Midnight Commander 安全漏洞
CVE-2023-45922 X11 Mesa 3D Graphics Library 安全漏洞
CVE-2023-45935 Qt 安全漏洞
CVE-2023-45924 libglvnd 安全漏洞
CVE-2023-45920 Xfig 安全漏洞
CVE-2023-45931 X11 Mesa 3D Graphics Library 安全漏洞
CVE-2023-45927 S-Lang 安全漏洞
CVE-2023-45913 X11 Mesa 3D Graphics Library 安全漏洞

Showing top 20 of 48 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2023-46046

No comments yet


Leave a comment