Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-6582

Опубликовано: 16 мар. 2020
Источник: debian
EPSS Низкий

Описание

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nagios-nrpefixed4.0.0-1package
nagios-nrpeno-dsabusterpackage
nagios-nrpeno-dsastretchpackage
nagios-nrpeno-dsajessiepackage

Примечания

  • https://herolab.usd.de/security-advisories/usd-2020-0001/

  • https://github.com/NagiosEnterprises/nrpe/commit/b84f9b8c9d290dd02e139df8dad1c3eb690c1213

  • https://github.com/NagiosEnterprises/nrpe/commit/8e3bea4e1b1937e395a182729762aa8894e8649e

  • https://github.com/NagiosEnterprises/nrpe/commit/0db345444d0dcb3e37cca1bcbb0027dcbb764197 (part validating incoming buffer size)

EPSS

Процентиль: 82%
0.01645
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

CVSS3: 7.5
redhat
почти 6 лет назад

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

CVSS3: 7.5
nvd
почти 6 лет назад

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

CVSS3: 7.5
github
больше 3 лет назад

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

EPSS

Процентиль: 82%
0.01645
Низкий