Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-4012

Опубликовано: 03 янв. 2019
Источник: nvd
CVSS3: 9
CVSS3: 8.1
CVSS2: 9.3
EPSS Низкий

Описание

An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud server to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:webroot:brightcloud:*:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03509
Низкий

9 Critical

CVSS3

8.1 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud server to trigger this vulnerability.

EPSS

Процентиль: 87%
0.03509
Низкий

9 Critical

CVSS3

8.1 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-119