Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8836

Опубликовано: 06 фев. 2015
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leading to a heap-based buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7fuseisoWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=863102fuseiso: Integer overflow, leading to heap buffer overflow when reading certain ISO ZF blocks

EPSS

Процентиль: 65%
0.00492
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 10 лет назад

Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leading to a heap-based buffer overflow.

CVSS3: 7.3
nvd
почти 10 лет назад

Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leading to a heap-based buffer overflow.

CVSS3: 7.3
debian
почти 10 лет назад

Integer overflow in the isofs_real_read_zf function in isofs.c in Fuse ...

CVSS3: 7.3
github
больше 3 лет назад

Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leading to a heap-based buffer overflow.

fstec
почти 10 лет назад

Уязвимость программного средства для монтирования образа диска FuseISO, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие

EPSS

Процентиль: 65%
0.00492
Низкий

6.8 Medium

CVSS2