Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4912

Опубликовано: 18 мая 2016
Источник: redhat
CVSS2: 5.4
EPSS Низкий

Описание

The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocation failure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6openslpWill not fix
Red Hat Enterprise Linux 7openslpWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1329295openslp: null pointer dereference in _xrealloc() function

EPSS

Процентиль: 73%
0.00785
Низкий

5.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocation failure.

CVSS3: 7.5
nvd
почти 9 лет назад

The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocation failure.

CVSS3: 7.5
msrc
4 месяца назад

The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service

CVSS3: 7.5
debian
почти 9 лет назад

The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remot ...

CVSS3: 7.5
github
больше 3 лет назад

The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocation failure.

EPSS

Процентиль: 73%
0.00785
Низкий

5.4 Medium

CVSS2