Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m3m-xv57-xrmm

Опубликовано: 13 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 7.1

Описание

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.1.2 before 6.1.2.21, from 5.3.1.40 before 5.3.1.41.

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.1.2 before 6.1.2.21, from 5.3.1.40 before 5.3.1.41.

EPSS

Процентиль: 43%
0.00208
Низкий

6.9 Medium

CVSS4

7.1 High

CVSS3

Дефекты

CWE-120
CWE-787

Связанные уязвимости

CVSS3: 7.1
nvd
около 1 года назад

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.1.2 before 6.1.2.21, from 5.3.1.40 before 5.3.1.41.

EPSS

Процентиль: 43%
0.00208
Низкий

6.9 Medium

CVSS4

7.1 High

CVSS3

Дефекты

CWE-120
CWE-787