Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-10739

Опубликовано: 21 янв. 2019
Источник: nvd
CVSS3: 5.3
CVSS2: 4.6
EPSS Низкий

Описание

In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*
Версия до 2.28 (включая)
Конфигурация 2
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

EPSS

Процентиль: 12%
0.0004
Низкий

5.3 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 7 лет назад

In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.

redhat
почти 10 лет назад

In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.

CVSS3: 5.3
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 5.3
debian
около 7 лет назад

In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinf ...

suse-cvrf
почти 7 лет назад

Security update for glibc

EPSS

Процентиль: 12%
0.0004
Низкий

5.3 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-20