Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20503

Опубликовано: 06 мар. 2020
Источник: debian
EPSS Низкий

Описание

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libusrsctpfixed0.9.3.0+20200312-1package
firefoxfixed74.0-1package
firefox-esrfixed68.6.0esr-1package
thunderbirdfixed1:68.6.0-1package
chromiumfixed80.0.3987.149-1package
chromiumend-of-lifestretchpackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-10/#CVE-2019-20503

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-09/#CVE-2019-20503

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-08/#CVE-2019-20503

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=1992

  • https://github.com/sctplab/usrsctp/commit/790a7a2555aefb392a5a69923f1e9d17b4968467

EPSS

Процентиль: 74%
0.00824
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

CVSS3: 6.1
redhat
больше 5 лет назад

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

CVSS3: 6.5
nvd
больше 5 лет назад

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

CVSS3: 6.5
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 6.5
github
около 3 лет назад

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

EPSS

Процентиль: 74%
0.00824
Низкий