Описание
The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is resolved in Puppet Enterprise 2016.4.3 and 2016.5.2.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2016.4.0 (включая) до 2016.4.3 (исключая)
Одно из
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet_enterprise:2016.5.1:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00522
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 5.3
debian
почти 9 лет назад
The Puppet Communications Protocol (PCP) Broker incorrectly validates ...
CVSS3: 5.3
github
больше 3 лет назад
The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is resolved in Puppet Enterprise 2016.4.3 and 2016.5.2.
EPSS
Процентиль: 66%
0.00522
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-20