Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-0767

Опубликовано: 13 фев. 2008
Источник: nvd
CVSS2: 5
EPSS Средний

Описание

ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large integer in this field in a packet to the Service Location Protocol (SLP) service on UDP port 427, triggering an out-of-bounds read.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:extremez:print_server:*:*:*:*:*:*:*:*
Версия до 5.1.2 (включая)
cpe:2.3:a:extremez-ip:file_server:*:*:*:*:*:*:*:*
Версия до 5.1.2 (включая)

EPSS

Процентиль: 93%
0.11404
Средний

5 Medium

CVSS2

Дефекты

CWE-189

Связанные уязвимости

github
почти 4 года назад

ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large integer in this field in a packet to the Service Location Protocol (SLP) service on UDP port 427, triggering an out-of-bounds read.

EPSS

Процентиль: 93%
0.11404
Средний

5 Medium

CVSS2

Дефекты

CWE-189