Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-20721

Опубликовано: 08 дек. 2018
Источник: redhat
CVSS3: 5.3

Описание

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParseEx functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

Отчет

This issue affects the versions of uriparser as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7uriparserFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1666023uriparser: Out-of-bounds read in uriParse*Ex*

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

CVSS3: 9.8
nvd
около 7 лет назад

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

CVSS3: 9.8
debian
около 7 лет назад

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bound ...

CVSS3: 9.8
github
больше 3 лет назад

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

CVSS3: 9.8
fstec
около 7 лет назад

Уязвимость функции URI_FUNC() компонента UriParse.c парсера Uriparser, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

5.3 Medium

CVSS3