Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000211

Опубликовано: 06 дек. 2017
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

Отчет

This issue did not affect the versions of lynx as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the versions of lynx as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5lynxNot affected
Red Hat Enterprise Linux 6lynxNot affected
Red Hat Enterprise Linux 7lynxWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1522617lynx: Use after free in HTML.c:HTML_put_string() can lead to memory disclosure

EPSS

Процентиль: 62%
0.0043
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 8 лет назад

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

CVSS3: 5.3
nvd
около 8 лет назад

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

CVSS3: 5.3
debian
около 8 лет назад

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML ...

suse-cvrf
около 8 лет назад

Security update for lynx

suse-cvrf
около 8 лет назад

Security update for lynx

EPSS

Процентиль: 62%
0.0043
Низкий

5.3 Medium

CVSS3