Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4q2r-xgxr-vvqm

Опубликовано: 22 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.

EPSS

Процентиль: 22%
0.00072
Низкий

9 Critical

CVSS3

Дефекты

CWE-121
CWE-787

Связанные уязвимости

CVSS3: 9
ubuntu
5 месяцев назад

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.

CVSS3: 6.6
redhat
5 месяцев назад

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.

CVSS3: 9
nvd
5 месяцев назад

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.

CVSS3: 9
debian
5 месяцев назад

Corosync through 3.1.9, if encryption is disabled or the attacker know ...

suse-cvrf
4 месяца назад

Security update for corosync

EPSS

Процентиль: 22%
0.00072
Низкий

9 Critical

CVSS3

Дефекты

CWE-121
CWE-787