Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-48038

Опубликовано: 11 сент. 2025
Источник: debian
EPSS Низкий

Описание

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
erlangfixed1:27.3.4.3+dfsg-1package
erlangfixed1:27.3.4.1+dfsg-1+deb13u1trixiepackage
erlangfixed1:25.2.3+dfsg-1+deb12u4bookwormpackage

Примечания

  • https://github.com/erlang/otp/security/advisories/GHSA-pvj7-9652-7h9r

  • https://github.com/erlang/otp/pull/10156

  • https://github.com/erlang/otp/commit/4e3bf86777ab3db7220c11d8ddabf15970ddd10a (OTP-27.3.4.3, OTP-28.0.3)

  • https://github.com/erlang/otp/commit/f09e0201ff701993dc24a08f15e524daf72db42f (OTP-26.2.5.15)

EPSS

Процентиль: 28%
0.00359
Низкий

Связанные уязвимости

ubuntu
11 месяцев назад

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.

CVSS3: 4.3
redhat
11 месяцев назад

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.

nvd
11 месяцев назад

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.

CVSS3: 4.3
msrc
11 месяцев назад

Unverified File Handles can Cause Excessive Use of System Resources

CVSS3: 4.3
fstec
11 месяцев назад

Уязвимость набора библиотек OTP языка программирования Erlang, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 28%
0.00359
Низкий