Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-17942

Опубликовано: 19 сент. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2partedNot affected
Red Hat Enterprise Linux 5coreutilsNot affected
Red Hat Enterprise Linux 5libvirtNot affected
Red Hat Enterprise Linux 6coreutilsNot affected
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 7coreutilsNot affected
Red Hat Enterprise Linux 7libvirtNot affected
Red Hat Enterprise Linux 8coreutilsNot affected
Red Hat Enterprise Linux 8libvirtNot affected
Red Hat Storage 3nagios-pluginsAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1635896gnulib: heap-based buffer overflow in convert_to_decimal function in vasnprintf.c

EPSS

Процентиль: 83%
0.02079
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 7 лет назад

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.

CVSS3: 8.8
nvd
почти 7 лет назад

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.

CVSS3: 8.8
debian
почти 7 лет назад

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018- ...

CVSS3: 8.8
github
больше 3 лет назад

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.

EPSS

Процентиль: 83%
0.02079
Низкий

3.3 Low

CVSS3