Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-29wm-wgxj-3pqf

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.

Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.

EPSS

Процентиль: 93%
0.09841
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 18 лет назад

Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.

EPSS

Процентиль: 93%
0.09841
Низкий

Дефекты

CWE-20