Описание
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| graphite2 | fixed | 1.3.15-2 | package | |
| graphite2 | fixed | 1.3.14-2+deb13u1 | trixie | package |
| graphite2 | fixed | 1.3.14-1+deb12u1 | bookworm | package |
| graphite2 | postponed | bullseye | package |
Примечания
Fixed by: https://github.com/silnrsi/graphite/commit/ad78c6b7319909e1540c1b134e115ced03417866 (1.3.15)
EPSS
Процентиль: 2%
0.00112
Низкий
Связанные уязвимости
CVSS3: 7.3
ubuntu
2 месяца назад
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
CVSS3: 7.3
nvd
2 месяца назад
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
EPSS
Процентиль: 2%
0.00112
Низкий