Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10689

Опубликовано: 02 мая 2018
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.

Отчет

Red Hat Product Security has rated this issue as having a security impact of Low, and a future update may address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5blktraceWill not fix
Red Hat Enterprise Linux 6blktraceWill not fix
Red Hat Enterprise Linux 8blktraceNot affected
Red Hat Enterprise Linux 7blktraceFixedRHSA-2019:216206.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1575119blktrace: buffer overflow in the dev_map_read function in btt/devmap.c

EPSS

Процентиль: 53%
0.00298
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.

CVSS3: 5.5
nvd
почти 8 лет назад

blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.

CVSS3: 5.5
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 5.5
debian
почти 8 лет назад

blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel a ...

suse-cvrf
почти 7 лет назад

Security update for blktrace

EPSS

Процентиль: 53%
0.00298
Низкий

4.8 Medium

CVSS3