Уязвимость некорректной работы методов Is*() для IPv4-маппированных IPv6-адресов
Описание
Различные методы Is*
(IsPrivate
, IsLoopback
и т.д.) работали некорректно для IPv4-маппированных IPv6-адресов, возвращая false
для адресов, которые в традиционной IPv4-форме вернули бы true
.
Тип уязвимости
Некорректная обработка данных
Ссылки
- Mailing ListThird Party Advisory
- Patch
- Issue Tracking
- Release Notes
- Third Party Advisory
- Mailing ListThird Party Advisory
- Patch
- Issue Tracking
- Release Notes
- Third Party Advisory
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
Дефекты
Связанные уязвимости
The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
The various Is methods (IsPrivate, IsLoopback, etc) did not work as ex ...
EPSS
9.8 Critical
CVSS3