Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4213

Опубликовано: 09 фев. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6jssNot affected
Red Hat Enterprise Linux 7jssNot affected
Red Hat Enterprise Linux 9jssNot affected
Red Hat Certificate System 10.4 for RHEL-8redhat-pkiFixedRHSA-2024:077412.02.2024
Red Hat Enterprise Linux 8pki-coreFixedRHSA-2022:185110.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2042900JSS: memory leak in TLS connection leads to OOM

EPSS

Процентиль: 39%
0.00172
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.

CVSS3: 7.5
nvd
почти 3 года назад

A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.

CVSS3: 7.5
debian
почти 3 года назад

A flaw was found in JSS, where it did not properly free up all memory. ...

rocky
около 3 лет назад

Moderate: pki-core:10.6 security and bug fix update

CVSS3: 7.5
github
почти 3 года назад

A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.

EPSS

Процентиль: 39%
0.00172
Низкий

7.5 High

CVSS3