Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-4904

Опубликовано: 06 мар. 2023
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:c-ares_project:c-ares:*:*:*:*:*:*:*:*
Версия до 1.19.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:software_collections:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00138
Низкий

8.6 High

CVSS3

Дефекты

CWE-20
CWE-1284

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 2 лет назад

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

CVSS3: 8.6
redhat
больше 2 лет назад

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

CVSS3: 8.6
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 8.6
debian
больше 2 лет назад

A flaw was found in the c-ares package. The ares_set_sortlist is missi ...

suse-cvrf
почти 2 года назад

Security update for libcares2

EPSS

Процентиль: 35%
0.00138
Низкий

8.6 High

CVSS3

Дефекты

CWE-20
CWE-1284