Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-32166

Опубликовано: 28 сент. 2022
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cloudbase:open_vswitch:*:*:*:*:*:*:*:*
Версия от 0.90.0 (включая) до 2.5.0 (включая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00548
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 3 лет назад

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

CVSS3: 8.6
redhat
больше 3 лет назад

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

CVSS3: 6.1
debian
больше 3 лет назад

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer o ...

suse-cvrf
около 3 лет назад

Security update for openvswitch

CVSS3: 8.8
github
больше 3 лет назад

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

EPSS

Процентиль: 67%
0.00548
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125