Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-0022

Опубликовано: 04 янв. 2019
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2019-0022: keepalived security update (IMPORTANT)

[1.3.5-8]

  • Fixed patch that was incorrectly removed (#1652694)

[1.3.5-7]

  • Fix buffer overflow when parsing HTTP status codes (#1652694)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

keepalived

1.3.5-8.el7_6

Oracle Linux x86_64

keepalived

1.3.5-8.el7_6

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.

CVSS3: 8.1
redhat
около 7 лет назад

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.

CVSS3: 9.8
nvd
около 7 лет назад

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.

CVSS3: 9.8
debian
около 7 лет назад

keepalived before 2.0.7 has a heap-based buffer overflow when parsing ...

CVSS3: 9.8
github
больше 3 лет назад

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.