Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000211

Опубликовано: 06 дек. 2017
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

Отчет

This issue did not affect the versions of lynx as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the versions of lynx as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5lynxNot affected
Red Hat Enterprise Linux 6lynxNot affected
Red Hat Enterprise Linux 7lynxWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1522617lynx: Use after free in HTML.c:HTML_put_string() can lead to memory disclosure

EPSS

Процентиль: 75%
0.01705
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 9 лет назад

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

CVSS3: 5.3
nvd
почти 9 лет назад

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

CVSS3: 5.3
debian
почти 9 лет назад

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML ...

suse-cvrf
больше 8 лет назад

Security update for lynx

suse-cvrf
больше 8 лет назад

Security update for lynx

EPSS

Процентиль: 75%
0.01705
Низкий

5.3 Medium

CVSS3