Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-6582

Опубликовано: 04 мар. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

A flaw was found in nrpe. A heap-based buffer overflow is possible due to the interpretation of a small negative number as a large positive number during a bzero call. The highest threat from this vulnerability is to system availability.

Отчет

Nagios is considered deprecated. Nagios plugins and Nagios server are no longer maintained or supported. Refer following release notes for details: "https://access.redhat.com/documentation/en-us/red_hat_gluster_storage/3.5/html-single/3.5_release_notes/index". The older version of nrpe which was shipped with Red Hat Gluster Storage does not support v3 packet format.

Меры по смягчению последствий

There is no known mitigation for this issue, the flaw can only be resolved by applying updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Storage 3nrpeNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1816813nrpe: heap-based buffer overflow due to a wrong integer type conversion

EPSS

Процентиль: 82%
0.01645
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

CVSS3: 7.5
nvd
почти 6 лет назад

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

CVSS3: 7.5
debian
почти 6 лет назад

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by ...

CVSS3: 7.5
github
больше 3 лет назад

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

EPSS

Процентиль: 82%
0.01645
Низкий

7.5 High

CVSS3