Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-41184

Опубликовано: 18 июл. 2024
Источник: debian
EPSS Низкий

Описание

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keepalivedfixed1:2.3.2-1package

Примечания

  • https://github.com/acassen/keepalived/commit/e78513fe0ce5d83c226ea2c0bd222f375c2438e7 (v2.3.2)

  • https://github.com/acassen/keepalived/issues/2447#issuecomment-2231329734

  • An empty ipset name must be explicitly configured by the user, no practical security impact

EPSS

Процентиль: 39%
0.0017
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 1 года назад

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

CVSS3: 6.3
redhat
больше 1 года назад

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

CVSS3: 9.8
nvd
больше 1 года назад

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

CVSS3: 9.8
msrc
около 1 года назад

Описание отсутствует

suse-cvrf
около 1 года назад

Security update for keepalived

EPSS

Процентиль: 39%
0.0017
Низкий
Уязвимость CVE-2024-41184