Описание
The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty className in a packet.
A NULL pointer dereference flaw was found in the way the lookupProviders() function processed certain requests without "className" information. An authenticated remote attacker could use this flaw to cause a denial of service (sfcbd crash) by sending a specially crafted request.
Отчет
This issue affects the versions of sblim-sfcb as shipped with Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | sblim-sfcb | Will not fix | ||
| Red Hat Enterprise Linux 7 | sblim-sfcb | Will not fix | ||
| Red Hat Enterprise Virtualization 3 | rhev-hypervisor | Affected |
Показывать по
Дополнительная информация
Статус:
2.7 Low
CVSS2
Связанные уязвимости
The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty className in a packet.
The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty className in a packet.
The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and ...
2.7 Low
CVSS2