CVE-2012-6123: Call-Cc Chicken

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."

Affected products

  • Call-Cc Chicken: before 4.8.0 (fixed in 4.8.0)
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only

Published 2019-10-31. Last modified 2026-06-16.