Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4356

Опубликовано: 08 апр. 2015
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libksbaWill not fix
Red Hat Enterprise Linux 6libksbaWill not fix
Red Hat Enterprise Linux 7libksbaWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-172->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1211259libksba: encoding of invalid utf-8 strings in DN decoder src/dn.c (append_quoted, append_atv)

EPSS

Процентиль: 76%
0.00956
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.

CVSS3: 7.5
nvd
больше 9 лет назад

The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.

CVSS3: 7.5
debian
больше 9 лет назад

The append_utf8_value function in the DN decoder (dn.c) in Libksba bef ...

CVSS3: 7.5
github
больше 3 лет назад

The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.

EPSS

Процентиль: 76%
0.00956
Низкий

5.1 Medium

CVSS2