Описание
Nicotine+ DoS on Null Character in Download Request
Denial of service (DoS) vulnerability in Nicotine+ starting with version 3.0.3 and prior to version 3.2.1 allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-45848
- https://github.com/nicotine-plus/nicotine-plus/issues/1777
- https://github.com/nicotine-plus/nicotine-plus/commit/0e3e2fac27a518f0a84330f1ddf1193424522045
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HWYV53KERFH2EC4XI2IVVQFTV75E5XM6
- https://security.gentoo.org/glsa/202210-20
Пакеты
Наименование
nicotine-plus
pip
Затронутые версииВерсия исправления
>= 3.0.3, < 3.2.1
3.2.1
Связанные уязвимости
CVSS3: 7.5
nvd
почти 4 года назад
Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.
CVSS3: 7.5
debian
почти 4 года назад
Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later all ...