Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16839

Опубликовано: 31 окт. 2018
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 1.0 on Red Hat Enterprise Linuxrh-dotnetcore10-curlOut of support scope
.NET Core 1.1 on Red Hat Enterprise Linuxrh-dotnetcore11-curlOut of support scope
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21-curlOut of support scope
Red Hat Enterprise Linux 5curlNot affected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected
Red Hat Enterprise Linux 8curlNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-curlAffected
Red Hat JBoss Web Server 5curlNot affected
Red Hat Software Collectionshttpd24-curlFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1642201curl: Integer overflow leading to heap-based buffer overflow in Curl_sasl_create_plain_message()

EPSS

Процентиль: 93%
0.05782
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 8 лет назад

Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.

CVSS3: 4.3
nvd
почти 8 лет назад

Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.

CVSS3: 4.3
debian
почти 8 лет назад

Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun ...

suse-cvrf
больше 7 лет назад

Security update for curl

CVSS3: 9.8
github
больше 4 лет назад

Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.

EPSS

Процентиль: 93%
0.05782
Низкий

5 Medium

CVSS3