Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-47085

Опубликовано: 26 нояб. 2023
Источник: redhat
CVSS3: 7.5

Описание

An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via the print_panic function in repo_checkout_filter.rs.

A flaw was found in print_panic function in the repo_checkout_filter.rs in ostree. By sending a specially crafted request, a remote attacker could cause a denial of service.

Отчет

This flaw is triggered by handling malicious input (via the print_panic function) causing denial of service, where the overall impact is considered minimal. The ostree versions as distributed with Red Hat Enterprise Linux 8 and 9 are not vulnerable to this flaw as further analysis showed both Red Hat Enterprise Linux were already shipping ostree 2022.7 which already contained the changes to eliminate this vulnerability from the code base. Additionally the vulnerable code path is not exposed to any attacker controlled input, closing the attack surface involved in this CVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ostreeOut of support scope
Red Hat Enterprise Linux 8ostreeNot affected
Red Hat Enterprise Linux 9ostreeNot affected
Red Hat OpenShift Container Platform 4ostreeAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2251641ostree: DoS via print_panic function

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via the print_panic function in repo_checkout_filter.rs.

CVSS3: 7.5
nvd
больше 2 лет назад

An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via the print_panic function in repo_checkout_filter.rs.

CVSS3: 7.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

An issue was discovered in ostree before 2022.7 allows attackers to ca ...

github
больше 2 лет назад

libostree vulnerable to denial of service attack

7.5 High

CVSS3