Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10243

Опубликовано: 04 апр. 2019
Источник: debian

Описание

htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libhtpfixed1:0.5.28-1package
suricatafixed1:4.0.0-1package
suricatano-dsastretchpackage

Примечания

  • suricata used the embedded copy of libhtp up to before 1:4.0.0-1.

  • https://github.com/OISF/libhtp/issues/169

  • https://github.com/OISF/libhtp/commit/eefd4b7d2be663f6067362f29c81e6edf909145a

  • https://suricata-ids.org/2018/07/18/suricata-4-0-5-available/

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 7 лет назад

htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.

CVSS3: 9.8
nvd
почти 7 лет назад

htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.

CVSS3: 9.8
github
больше 3 лет назад

htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.