CVE-2026-103436
LOW
3,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf('%*s %*s %s', answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.
457
Use of Uninitialized Variable
DraftCommon Consequences
Security Scopes Affected:
Availability
Integrity
Other
Authorization
Potential Impacts:
Other
Applicable Platforms
Languages:
C, C++, Perl, PHP, Not Language-Specific
https://bugzilla.redhat.com/show_bug.cgi?id=2493140
https://github.com/therealbstern/apcupsd/blob/224d19d5faa508d04267f6135fe53d508…
https://sourceforge.net/projects/apcupsd/