Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r75-vj28-w5c7

Опубликовано: 17 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

EPSS

Процентиль: 84%
0.02289
Низкий

7.8 High

CVSS3

Дефекты

CWE-704

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

CVSS3: 7.8
nvd
почти 4 года назад

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

CVSS3: 7.8
debian
почти 4 года назад

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecke ...

suse-cvrf
больше 4 лет назад

Security update for isync

EPSS

Процентиль: 84%
0.02289
Низкий

7.8 High

CVSS3

Дефекты

CWE-704