Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44847

Опубликовано: 13 дек. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:toktok:toxcore:*:*:*:*:*:*:*:*
Версия от 0.1.9 (включая) до 0.1.11 (включая)
cpe:2.3:a:toktok:toxcore:*:*:*:*:*:*:*:*
Версия от 0.2.0 (включая) до 0.2.12 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.03947
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-682

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 4 лет назад

A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.

CVSS3: 9.8
debian
около 4 лет назад

A stack-based buffer overflow in handle_request function in DHT.c in t ...

suse-cvrf
около 4 лет назад

Security update for c-toxcore

CVSS3: 9.8
github
около 4 лет назад

A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.

EPSS

Процентиль: 88%
0.03947
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-682