Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-5544

Опубликовано: 06 дек. 2019
Источник: redhat
CVSS3: 9.8
EPSS Критический

Описание

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

A heap overflow vulnerability was found in OpenSLP. An attacker could use this flaw to gain remote code execution.

Отчет

This issue did not affect the versions of openslp as shipped with Red Hat Enterprise Linux 8 as they did not include the slpd service component.

Меры по смягчению последствий

There is no known mitigation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8openslpNot affected
Red Hat Enterprise Linux 9openslpNot affected
Red Hat Enterprise Linux 6openslpFixedRHSA-2020:019922.01.2020
Red Hat Enterprise Linux 7openslpFixedRHSA-2019:424016.12.2019

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1777788openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution

EPSS

Процентиль: 100%
0.92688
Критический

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

CVSS3: 9.8
nvd
около 6 лет назад

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

CVSS3: 9.8
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 9.8
debian
около 6 лет назад

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap ove ...

CVSS3: 9.8
github
больше 3 лет назад

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

EPSS

Процентиль: 100%
0.92688
Критический

9.8 Critical

CVSS3