Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-43612

Опубликовано: 18 нояб. 2021
Источник: redhat
CVSS3: 7.3

Описание

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.

An out-of-bounds read vulnerability is present in lldpd. An attacker on the same network as the vulnerable system may use this vulnerability to leak memory data from the application or crash it by sending shorter SONMP packets than what is expected.

Отчет

The Impact of this flaw has been set to Moderate, as it generally results in leak of data or, in some particular circumstances, in a crash of the application. Moreover, it requires an attacker to be adjacent to the vulnerable system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8lldpdWill not fix
Red Hat Enterprise Linux 9lldpdFixedRHSA-2024:915812.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2040388lldpd: out-of-bounds read when decoding SONMP packets

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.

CVSS3: 7.5
nvd
около 2 лет назад

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.

CVSS3: 7.5
debian
около 2 лет назад

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decod ...

CVSS3: 7.5
github
около 2 лет назад

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.

oracle-oval
8 месяцев назад

ELSA-2024-9158: lldpd security update (MODERATE)

7.3 High

CVSS3