Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-26g9-q99r-c973

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

EPSS

Процентиль: 32%
0.00124
Низкий

8.4 High

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 8.4
ubuntu
почти 8 лет назад

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

CVSS3: 8.4
nvd
почти 8 лет назад

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

CVSS3: 8.4
debian
почти 8 лет назад

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the sessio ...

suse-cvrf
больше 6 лет назад

Security update for xrdp

suse-cvrf
больше 6 лет назад

Security update for xrdp

EPSS

Процентиль: 32%
0.00124
Низкий

8.4 High

CVSS3

Дефекты

CWE-119