Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2675

Опубликовано: 03 сент. 2014
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.

It was found that the OAuth implementation in librest, a helper library for RESTful services, incorrectly truncated the pointer returned by the rest_proxy_call_get_url call. An attacker could use this flaw to crash an application using the librest library.

Дополнительная информация

Статус:

Low
Дефект:
CWE-704
https://bugzilla.redhat.com/show_bug.cgi?id=1199049rest: memory corruption when using oauth because of implicit declaration of rest_proxy_call_get_url

EPSS

Процентиль: 86%
0.03052
Низкий

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.

CVSS3: 7.5
nvd
около 8 лет назад

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.

CVSS3: 7.5
debian
около 8 лет назад

The OAuth implementation in librest before 0.7.93 incorrectly truncate ...

CVSS3: 7.5
github
больше 3 лет назад

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.

oracle-oval
почти 10 лет назад

ELSA-2015-2237: rest security update (LOW)

EPSS

Процентиль: 86%
0.03052
Низкий

2.1 Low

CVSS2