Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-285f-828q-q7g5

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.5

Описание

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

EPSS

Процентиль: 3%
0.0013
Низкий

6.9 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 5.5
ubuntu
8 месяцев назад

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

CVSS3: 4
redhat
8 месяцев назад

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

CVSS3: 5.5
nvd
8 месяцев назад

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

CVSS3: 5.5
debian
8 месяцев назад

NULL pointer dereference in TagSection.keys() in python-apt on APT-bas ...

CVSS3: 5.5
fstec
больше 1 года назад

Уязвимость функции TagSection.keys() компонента tag.cc модуля для установки пакетов Python APT, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 3%
0.0013
Низкий

6.9 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-476