Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-43618

Опубликовано: 15 нояб. 2021
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.

A flaw was found in gmp. An integer overflow vulnerability could allow an attacker to input an integer value leading to a crash. The highest threat from this vulnerability is to system availability.

Отчет

Exploitation is only possible on 32-bit systems. The susceptible GMP package is not tethered to the network stack, so it can only be exploited via a file already on the local system. This can be achieved either by the attacker gaining local login credentials or alternatively; by tricking a user into loading then executing a malicious file. Because of these combined reasons Red Hat Product Security rates the impact as Moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gmpOut of support scope
Red Hat Enterprise Linux 7gmpOut of support scope
Red Hat Enterprise Linux 8gmpFixedRHSA-2024:321422.05.2024
Red Hat Enterprise Linux 8.6 Extended Update SupportgmpFixedRHSA-2024:110205.03.2024
Red Hat Enterprise Linux 8.8 Extended Update SupportgmpFixedRHSA-2024:141219.03.2024
Red Hat Enterprise Linux 9gmpFixedRHSA-2023:666107.11.2023
Red Hat Enterprise Linux 9gmpFixedRHSA-2023:666107.11.2023
RHOL-5.6-RHEL-8openshift-logging/cluster-logging-operator-bundleFixedRHSA-2024:209201.05.2024
RHOL-5.6-RHEL-8openshift-logging/cluster-logging-rhel8-operatorFixedRHSA-2024:209201.05.2024
RHOL-5.6-RHEL-8openshift-logging/elasticsearch6-rhel8FixedRHSA-2024:209201.05.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2024904gmp: Integer overflow and resultant buffer overflow via crafted input

EPSS

Процентиль: 65%
0.00501
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.

CVSS3: 7.5
nvd
почти 4 года назад

GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.

CVSS3: 7.5
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7.5
debian
почти 4 года назад

GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an m ...

suse-cvrf
больше 3 лет назад

Security update for gmp

EPSS

Процентиль: 65%
0.00501
Низкий

6.2 Medium

CVSS3

Уязвимость CVE-2021-43618