Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-674g-g96j-pr63

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.

In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.

EPSS

Процентиль: 65%
0.00484
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.

CVSS3: 9.8
nvd
около 9 лет назад

In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.

CVSS3: 9.8
debian
около 9 лет назад

In Botan 1.8.0 through 1.11.33, when decoding BER data an integer over ...

suse-cvrf
больше 8 лет назад

Security update for Botan

suse-cvrf
больше 8 лет назад

Security update for Botan

EPSS

Процентиль: 65%
0.00484
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190