Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-41184

Опубликовано: 18 июл. 2024
Источник: debian
EPSS Низкий

Описание

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keepalivedfixed1:2.3.2-1package

Примечания

  • https://github.com/acassen/keepalived/commit/e78513fe0ce5d83c226ea2c0bd222f375c2438e7 (v2.3.2)

  • https://github.com/acassen/keepalived/issues/2447#issuecomment-2231329734

  • An empty ipset name must be explicitly configured by the user, no practical security impact

EPSS

Процентиль: 50%
0.00269
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
11 месяцев назад

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

CVSS3: 6.3
redhat
11 месяцев назад

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

CVSS3: 9.8
nvd
11 месяцев назад

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

CVSS3: 9.8
msrc
8 месяцев назад

Описание отсутствует

suse-cvrf
8 месяцев назад

Security update for keepalived

EPSS

Процентиль: 50%
0.00269
Низкий