Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1000524

Опубликовано: 26 июн. 2018
Источник: nvd
CVSS3: 5.5
CVSS2: 4.3
EPSS Низкий

Описание

miniSphere version 5.2.9 and earlier contains a Integer Overflow vulnerability in layer_resize() function in map_engine.c that can result in remote denial of service. This attack appear to be exploitable via the victim must load a specially-crafted map which calls SetLayerSize in its entry script. This vulnerability appears to have been fixed in 5.0.3, 5.1.5, 5.2.10 and later.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:spheredev:minisphere:*:*:*:*:*:*:*:*
Версия до 5.2.9 (включая)

EPSS

Процентиль: 48%
0.00252
Низкий

5.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

miniSphere version 5.2.9 and earlier contains a Integer Overflow vulnerability in layer_resize() function in map_engine.c that can result in remote denial of service. This attack appear to be exploitable via the victim must load a specially-crafted map which calls SetLayerSize in its entry script. This vulnerability appears to have been fixed in 5.0.3, 5.1.5, 5.2.10 and later.

EPSS

Процентиль: 48%
0.00252
Низкий

5.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-190