Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20795

Опубликовано: 05 мая 2019
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.

A use-after-free flaw was found in iproute in the network namespace management component of the ip command-line utility. This flaw allows a local attacker to crash the program while displaying network namespaces. The highest threat from this vulnerability is to system availability.

Отчет

This issue affects the versions of iproute as shipped with Red Hat Enterprise Linux 7. Red Hat Enterprise Linux 8 is not affected by this flaw. This flaw has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Red Hat Enterprise Linux 5 is now in the Extended Life Phase of the support and maintenance life cycle. Red Hat Enterprise Linux 6 is now in the Maintenance Support 2 Phase of the support and maintenance life cycle. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5iprouteOut of support scope
Red Hat Enterprise Linux 6iprouteOut of support scope
Red Hat Enterprise Linux 7iprouteFix deferred
Red Hat Enterprise Linux 8iprouteNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1868211iproute: use-after-free in get_netnsid_from_name in ip/ipnetns.c

EPSS

Процентиль: 8%
0.0003
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 5 лет назад

iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.

CVSS3: 4.4
nvd
больше 5 лет назад

iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.

CVSS3: 4.4
debian
больше 5 лет назад

iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ...

suse-cvrf
больше 4 лет назад

Security update for iproute2

github
больше 3 лет назад

iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c.

EPSS

Процентиль: 8%
0.0003
Низкий

4.4 Medium

CVSS3