Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-37536

Опубликовано: 11 окт. 2023
Источник: redhat
CVSS3: 8.8

Описание

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

An integer overflow exists in xerces-c++. This flaw allows an attacker using a specially crafted HTTP request payload to trigger an out-of-bounds read, resulting in a loss of confidentiality, integrity, and availability.

Отчет

RHEL-6 is Out of Support Scope. https://access.redhat.com/articles/4997301

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xerces-cOut of support scope
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxerces-cFixedRHSA-2024:879504.11.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2243426xerces-c: An integer overflow issue that allows remote attackers to cause out-of-bound access via HTTP request

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 1 года назад

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

CVSS3: 8.2
nvd
больше 1 года назад

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

CVSS3: 8.2
debian
больше 1 года назад

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remo ...

suse-cvrf
больше 1 года назад

Security update for xerces-c

suse-cvrf
больше 1 года назад

Security update for xerces-c

8.8 High

CVSS3