Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5704

Опубликовано: 16 янв. 2018
Источник: debian

Описание

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openocdfixed0.10.0-4package

Примечания

  • https://sourceforge.net/p/openocd/mailman/message/36188041/

  • http://openocd.zylin.com/4330

  • http://openocd.zylin.com/4331

  • http://openocd.zylin.com/4335

Связанные уязвимости

CVSS3: 9.6
ubuntu
около 8 лет назад

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

CVSS3: 9.6
nvd
около 8 лет назад

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

CVSS3: 9.6
github
больше 3 лет назад

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.