Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-12658

Опубликовано: 31 дек. 2020
Источник: redhat
CVSS3: 0
EPSS Низкий

Описание

gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem.

Отчет

Red Hat Product Security does not view this as a security vulnerability because no service will be denied since the bug is triggered on an exit path of the program, which means that the program would already be stopping service and thus a malicious attacker would gain no impact to availability by triggering the bug.

Дополнительная информация

Дефект:
CWE-667
https://bugzilla.redhat.com/show_bug.cgi?id=1918258gssproxy: not unlocking cond_mutex before pthread exit in gp_worker_main() in gp_workers.c

EPSS

Процентиль: 68%
0.00572
Низкий

0 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem.

CVSS3: 9.8
nvd
около 5 лет назад

gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem.

CVSS3: 9.8
debian
около 5 лет назад

gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex befor ...

suse-cvrf
почти 5 лет назад

Security update for gssproxy

suse-cvrf
почти 5 лет назад

Security update for gssproxy

EPSS

Процентиль: 68%
0.00572
Низкий

0 Low

CVSS3