Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20721

Опубликовано: 16 янв. 2019
Источник: debian
EPSS Низкий

Описание

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
uriparserfixed0.9.1-1package

Примечания

  • https://github.com/uriparser/uriparser/commit/cef25028de5ff872c2e1f0a6c562eb3ea9ecbce4

EPSS

Процентиль: 66%
0.00513
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

CVSS3: 5.3
redhat
около 7 лет назад

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

CVSS3: 9.8
nvd
около 7 лет назад

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

CVSS3: 9.8
github
больше 3 лет назад

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

CVSS3: 9.8
fstec
около 7 лет назад

Уязвимость функции URI_FUNC() компонента UriParse.c парсера Uriparser, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 66%
0.00513
Низкий