Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3804

Опубликовано: 26 мар. 2019
Источник: debian

Описание

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cockpitfixed184-1package

Примечания

  • https://github.com/cockpit-project/cockpit/pull/10819

  • https://github.com/cockpit-project/cockpit/commit/c51f6177576d7e12

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

CVSS3: 7.5
redhat
около 7 лет назад

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

CVSS3: 7.5
nvd
почти 7 лет назад

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

CVSS3: 7.5
github
больше 3 лет назад

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

oracle-oval
почти 7 лет назад

ELSA-2019-0482: cockpit security update (MODERATE)