Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3804

Опубликовано: 26 мар. 2019
Источник: debian
EPSS Низкий

Описание

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cockpitfixed184-1package

Примечания

  • https://github.com/cockpit-project/cockpit/pull/10819

  • https://github.com/cockpit-project/cockpit/commit/c51f6177576d7e12

EPSS

Процентиль: 91%
0.04858
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

CVSS3: 7.5
redhat
больше 7 лет назад

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

CVSS3: 7.5
nvd
больше 7 лет назад

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

CVSS3: 7.5
github
около 4 лет назад

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

oracle-oval
больше 7 лет назад

ELSA-2019-0482: cockpit security update (MODERATE)

EPSS

Процентиль: 91%
0.04858
Низкий
Уязвимость CVE-2019-3804