Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-8754

Опубликовано: 18 мар. 2018
Источник: debian
EPSS Низкий

Описание

The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values of user SID data size, strings size, or data size. NOTE: the vendor has disputed this as described in libyal/libevt issue 5 on GitHub

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libevtfixed20180317-1package

Примечания

  • https://github.com/libyal/libevt/commit/444ca3ce7853538c577e0ec3f6146d2d65780734

  • Impact limited to OOB read, not write

EPSS

Процентиль: 16%
0.0005
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values of user SID data size, strings size, or data size. NOTE: the vendor has disputed this as described in libyal/libevt issue 5 on GitHub

CVSS3: 5.5
nvd
почти 8 лет назад

The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values of user SID data size, strings size, or data size. NOTE: the vendor has disputed this as described in libyal/libevt issue 5 on GitHub

CVSS3: 5.5
github
больше 3 лет назад

** DISPUTED ** The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values of user SID data size, strings size, or data size. NOTE: the vendor has disputed this as described in libyal/libevt issue 5 on GitHub.

EPSS

Процентиль: 16%
0.0005
Низкий