Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000121

Опубликовано: 14 мар. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service

A NULL pointer dereference flaw was found in the way libcurl checks values returned by the openldap ldap_get_attribute_ber() function. A malicious LDAP server could use this flaw to crash a libcurl client application via a specially crafted LDAP reply.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 1.0 on Red Hat Enterprise Linuxrh-dotnetcore10-curlOut of support scope
.NET Core 1.1 on Red Hat Enterprise Linuxrh-dotnetcore11-curlOut of support scope
.NET Core 2.0 on Red Hat Enterprise Linuxrh-dotnet20-curlOut of support scope
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21-curlWill not fix
Red Hat Ceph Storage 2curlWill not fix
Red Hat Enterprise Linux 5curlNot affected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 8curlNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-curlAffected
JBoss Core Services Apache HTTP Server 2.4.29 SP2FixedRHSA-2019:154318.06.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1552631curl: LDAP NULL pointer dereference

EPSS

Процентиль: 86%
0.02809
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service

CVSS3: 7.5
nvd
больше 7 лет назад

A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service

CVSS3: 7.5
debian
больше 7 лет назад

A NULL pointer dereference exists in curl 7.21.0 to and including curl ...

CVSS3: 7.5
github
больше 3 лет назад

A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service

suse-cvrf
больше 7 лет назад

Security update for curl

EPSS

Процентиль: 86%
0.02809
Низкий

5.3 Medium

CVSS3