Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5185

Опубликовано: 20 авг. 2015
Источник: redhat
CVSS2: 2.7

Описание

The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty className in a packet.

A NULL pointer dereference flaw was found in the way the lookupProviders() function processed certain requests without "className" information. An authenticated remote attacker could use this flaw to cause a denial of service (sfcbd crash) by sending a specially crafted request.

Отчет

This issue affects the versions of sblim-sfcb as shipped with Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sblim-sfcbWill not fix
Red Hat Enterprise Linux 7sblim-sfcbWill not fix
Red Hat Enterprise Virtualization 3rhev-hypervisorAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1255587sblim-sfcb: lookupProviders() null pointer dereference

2.7 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty className in a packet.

nvd
больше 10 лет назад

The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty className in a packet.

debian
больше 10 лет назад

The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and ...

suse-cvrf
около 10 лет назад

Security update for sblim-sfcb

suse-cvrf
около 10 лет назад

Security update for sblim-sfcb

2.7 Low

CVSS2