CVE-2012-6089: Swi-Prolog

High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.

Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

Affected products

  • Swi-Prolog Swi-Prolog: up to and including 6.2.4; version 5.6.50 only; version 5.6.51 only; version 5.6.52 only; version 5.6.53 only; version 5.6.54 only; …

Published 2013-01-04. Last modified 2026-06-16.