Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-43082

Опубликовано: 03 нояб. 2021
Источник: debian

Описание

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
trafficserverfixed9.1.1+ds-1package
trafficservernot-affectedbullseyepackage
trafficservernot-affectedbusterpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2021/11/02/11

  • https://github.com/apache/trafficserver/pull/8475

  • https://github.com/apache/trafficserver/commit/02b17dbe3cff71ffd31577d872e077531124d207 (master)

  • CVE description is wrong, this doesn't affect 8.1, only 9.x/master:

  • Introduced with https://github.com/apache/trafficserver/commit/5e2385b666b4176be0f64fbadfbfae42094db396 (9.1.0-rc0)

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.

CVSS3: 9.8
nvd
больше 4 лет назад

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.

github
больше 3 лет назад

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость плагина stats-over-http веб-сервера Apache Traffic Server, позволяющая нарушителю вызвать отказ в обслуживании