Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4459

Опубликовано: 12 окт. 2016
Источник: redhat
CVSS3: 4.8
CVSS2: 3.8
EPSS Низкий

Описание

Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.

It was discovered that specifying configuration with a JVMRoute path longer than 80 characters will cause segmentation fault leading to a server crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 2mod_clusterWill not fix
Red Hat JBoss Enterprise Web Server 3mod_clusterAffected
JBoss Core Services on RHEL 6jbcs-httpd24-httpdFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_auth_kerbFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_bmxFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_cluster-nativeFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_jkFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_rtFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_securityFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-nghttp2FixedRHSA-2017:019325.01.2017

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1341583mod_cluster: Buffer overflow in mod_manager when sending request with long JVMRoute

EPSS

Процентиль: 81%
0.01537
Низкий

4.8 Medium

CVSS3

3.8 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
nvd
почти 9 лет назад

Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.

CVSS3: 7.5
debian
почти 9 лет назад

Stack-based buffer overflow in native/mod_manager/node.c in mod_cluste ...

CVSS3: 7.5
github
больше 3 лет назад

Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.

EPSS

Процентиль: 81%
0.01537
Низкий

4.8 Medium

CVSS3

3.8 Low

CVSS2