Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-75m6-wc48-gvw9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and builder. HTTP parser has a heap buffer overflow (OOB write). In default configuration camera parses responses only from HTTPS URLs from config file, so vulnerable code is unreachable and one more bug required to reach it.

Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and builder. HTTP parser has a heap buffer overflow (OOB write). In default configuration camera parses responses only from HTTPS URLs from config file, so vulnerable code is unreachable and one more bug required to reach it.

EPSS

Процентиль: 69%
0.00593
Низкий

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and builder. HTTP parser has a heap buffer overflow (OOB write). In default configuration camera parses responses only from HTTPS URLs from config file, so vulnerable code is unreachable and one more bug required to reach it.

EPSS

Процентиль: 69%
0.00593
Низкий

Дефекты

CWE-787