Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-4087

Опубликовано: 21 нояб. 2022
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to information exposure through discrepancy. The name of the patch is 186306d6199096b7a7c4b4574d4be8cdb8426729. It is recommended to apply a patch to fix this issue. VDB-214054 is the identifier assigned to this vulnerability.

A vulnerability was found in ipxe. This issue affects the tls_new_ciphertext function in the src/net/tls.c file of the TLS component. The manipulation of the pad_len argument leads to information exposure due to discrepancy.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ipxeOut of support scope
Red Hat Enterprise Linux 8ipxeNot affected
Red Hat Enterprise Linux 9ipxeNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
Дефект:
CWE-203
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2144985ipxe: Padding oracle attack vulnerability

EPSS

Процентиль: 22%
0.00071
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.6
ubuntu
больше 2 лет назад

A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to information exposure through discrepancy. The name of the patch is 186306d6199096b7a7c4b4574d4be8cdb8426729. It is recommended to apply a patch to fix this issue. VDB-214054 is the identifier assigned to this vulnerability.

CVSS3: 2.6
nvd
больше 2 лет назад

A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to information exposure through discrepancy. The name of the patch is 186306d6199096b7a7c4b4574d4be8cdb8426729. It is recommended to apply a patch to fix this issue. VDB-214054 is the identifier assigned to this vulnerability.

CVSS3: 2.6
debian
больше 2 лет назад

A vulnerability was found in iPXE. It has been declared as problematic ...

CVSS3: 4.3
redos
около 1 года назад

Уязвимость ipxe

CVSS3: 4.3
github
больше 2 лет назад

A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to information exposure through discrepancy. The name of the patch is 186306d6199096b7a7c4b4574d4be8cdb8426729. It is recommended to apply a patch to fix this issue. VDB-214054 is the identifier assigned to this vulnerability.

EPSS

Процентиль: 22%
0.00071
Низкий

4.3 Medium

CVSS3