Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v7h6-g695-5j7q

Опубликовано: 07 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

EPSS

Процентиль: 35%
0.00138
Низкий

8.6 High

CVSS3

Дефекты

CWE-119
CWE-1284
CWE-20

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 2 лет назад

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

CVSS3: 8.6
redhat
больше 2 лет назад

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

CVSS3: 8.6
nvd
больше 2 лет назад

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

CVSS3: 8.6
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 8.6
debian
больше 2 лет назад

A flaw was found in the c-ares package. The ares_set_sortlist is missi ...

EPSS

Процентиль: 35%
0.00138
Низкий

8.6 High

CVSS3

Дефекты

CWE-119
CWE-1284
CWE-20