Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3gg-c3fx-2m67

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.

EPSS

Процентиль: 96%
0.2525
Средний

8.1 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 8 лет назад

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.

CVSS3: 8.1
nvd
больше 8 лет назад

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.

CVSS3: 8.1
debian
больше 8 лет назад

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2 ...

suse-cvrf
больше 8 лет назад

Recommended update for gsoap

EPSS

Процентиль: 96%
0.2525
Средний

8.1 High

CVSS3

Дефекты

CWE-190