Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-41043

Опубликовано: 05 янв. 2022
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.

A heap use-after-free flaw was found in tcpslices' extract_slice(). This flaw allows an attacker with local network access to pass a specially crafted 'pcap' file to tcpslice, causing segmentation fault. This vulnerability halts or crashes the application, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tcpdumpOut of support scope
Red Hat Enterprise Linux 7tcpdumpOut of support scope
Red Hat Enterprise Linux 8tcpdumpFixedRHSA-2024:076912.02.2024
Red Hat Enterprise Linux 8.6 Extended Update SupporttcpdumpFixedRHSA-2024:041025.01.2024
Red Hat Enterprise Linux 8.8 Extended Update SupporttcpdumpFixedRHSA-2024:057130.01.2024
Red Hat Enterprise Linux 9tcpdumpFixedRHSA-2024:221130.04.2024
Red Hat Enterprise Linux 9.2 Extended Update SupporttcpdumpFixedRHSA-2024:109005.03.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2040392tcpslice: use-after-free in extract_slice()

EPSS

Процентиль: 47%
0.00243
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.

CVSS3: 5.5
nvd
больше 3 лет назад

Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.

CVSS3: 5.5
debian
больше 3 лет назад

Use after free in tcpslice triggers AddressSanitizer, no other confirm ...

rocky
больше 1 года назад

Moderate: tcpdump security update

github
больше 3 лет назад

Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.

EPSS

Процентиль: 47%
0.00243
Низкий

5.5 Medium

CVSS3