Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28q9-rp4x-j7g7

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences.

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences.

EPSS

Процентиль: 96%
0.29192
Средний

9.8 Critical

CVSS3

Дефекты

CWE-119
CWE-131

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 21 года назад

Описание отсутствует

CVSS3: 9.8
nvd
больше 21 года назад

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.

CVSS3: 9.8
debian
больше 21 года назад

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allo ...

EPSS

Процентиль: 96%
0.29192
Средний

9.8 Critical

CVSS3

Дефекты

CWE-119
CWE-131