Описание
regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.
Ссылки
- Mailing ListPatchThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Mailing ListPatchThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*
Конфигурация 2Версия до 1.14 (включая)
cpe:2.3:a:gnu:ed:*:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01019
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-416
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 9 лет назад
regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.
CVSS3: 3.3
redhat
около 9 лет назад
regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.
CVSS3: 7.5
debian
почти 9 лет назад
regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of ...
EPSS
Процентиль: 77%
0.01019
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-416