Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-18409

Опубликовано: 17 окт. 2018
Источник: debian
EPSS Низкий

Описание

A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogram call or a get_histogram call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tcpflowfixed1.5.2+repack1-1package

Примечания

  • https://github.com/simsong/tcpflow/issues/195

  • https://github.com/simsong/tcpflow/commit/89c04b4fb0e46b3c4f1388686e83966e531cbea9

  • Crash in CLI tool, no security impact

EPSS

Процентиль: 55%
0.00323
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogram call or a get_histogram call.

CVSS3: 5.5
nvd
больше 7 лет назад

A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogram call or a get_histogram call.

CVSS3: 5.5
github
больше 3 лет назад

A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogram call or a get_histogram call.

EPSS

Процентиль: 55%
0.00323
Низкий