Описание
LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_item_print).
Ссылки
- ExploitIssue TrackingPatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- ExploitIssue TrackingPatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.9.1 (включая) до 3.2.1 (включая)
Одновременно
cpe:2.3:a:openbsd:libressl:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.00221
Низкий
7.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-125
Связанные уязвимости
CVSS3: 7.1
debian
больше 4 лет назад
LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_p ...
github
больше 3 лет назад
LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_item_print).
EPSS
Процентиль: 44%
0.00221
Низкий
7.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-125