Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5397

Опубликовано: 12 фев. 2018
Источник: debian
EPSS Средний

Описание

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
thrift-compilerunfixedpackage
thriftfixed0.10.0-1experimentalpackage
thriftfixed0.11.0-3package

Примечания

  • https://issues.apache.org/jira/browse/THRIFT-3893

  • https://github.com/apache/thrift/commit/2007783e874d524a46b818598a45078448ecc53e

  • Fixed in 0.10.0 upstream, and in experimental src:thrift/0.10.0-1 is present

  • src:thrift only present in experimental

  • Go bindings only enabled in 0.9.3-2 (not yet in unstable)

  • Only ever affected src:thrift in experimental, and fixed in src:thrift/0.10.0-1

  • so any future upload of thrift to unstable can mark this item as <not-affected>

  • (fixed before the initial upload to Debian unstable)

EPSS

Процентиль: 96%
0.22566
Средний

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 7.8
redhat
больше 9 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 8.8
nvd
почти 8 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 8.8
github
больше 3 лет назад

Apache Thrift Go Library Command Injection

EPSS

Процентиль: 96%
0.22566
Средний