Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-37600

Опубликовано: 30 июл. 2021
Источник: debian
EPSS Низкий

Описание

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
util-linuxfixed2.36.1-8package
util-linuxno-dsastretchpackage

Примечания

  • https://github.com/karelzak/util-linux/issues/1395

  • https://github.com/karelzak/util-linux/commit/1c9143d0c1f979c3daf10e1c37b5b1e916c22a1c

EPSS

Процентиль: 17%
0.00054
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.

CVSS3: 4.7
redhat
больше 4 лет назад

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.

CVSS3: 5.5
nvd
больше 4 лет назад

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.

CVSS3: 5.5
msrc
больше 4 лет назад

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments and possibly in all realistic environments.

suse-cvrf
больше 4 лет назад

Security update for util-linux

EPSS

Процентиль: 17%
0.00054
Низкий