Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10253

Опубликовано: 19 июн. 2016
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)erlangWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)erlangWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)erlangWill not fix
Red Hat OpenStack Platform 10 (Newton)erlangWill not fix
Red Hat OpenStack Platform 11 (Ocata)erlangWill not fix
Red Hat OpenStack Platform 12 (Pike)erlangNot affected
Red Hat OpenStack Platform 8 (Liberty)erlangWill not fix
Red Hat OpenStack Platform 9 (Mitaka)erlangWill not fix
Red Hat Storage Console 2erlangWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1433985erlang: Heap-buffer overflow via regular expressions

EPSS

Процентиль: 66%
0.00513
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.

CVSS3: 9.8
nvd
почти 9 лет назад

An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.

CVSS3: 9.8
debian
почти 9 лет назад

An issue was discovered in Erlang/OTP 18.x. Erlang's generation of com ...

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.

EPSS

Процентиль: 66%
0.00513
Низкий

4.4 Medium

CVSS3