Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8hx-vf7j-v5q3

Опубликовано: 10 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code, because those lookup values lead to incorrect length calculations and incorrect memcpy operations.

In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code, because those lookup values lead to incorrect length calculations and incorrect memcpy operations.

EPSS

Процентиль: 41%
0.00194
Низкий

9 Critical

CVSS3

Дефекты

CWE-392

Связанные уязвимости

CVSS3: 9
ubuntu
10 месяцев назад

In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code, because those lookup values lead to incorrect length calculations and incorrect memcpy operations.

CVSS3: 9
nvd
10 месяцев назад

In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code, because those lookup values lead to incorrect length calculations and incorrect memcpy operations.

CVSS3: 9
debian
10 месяцев назад

In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c ...

CVSS3: 9
fstec
10 месяцев назад

Уязвимость функции ns_resolv() диспетчера соединений ConnMan, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 41%
0.00194
Низкий

9 Critical

CVSS3

Дефекты

CWE-392