Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-41184

Опубликовано: 18 июл. 2024
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

A flaw was found in the keepalived package. An integer overflow occurs when incorrect arguments are passed. As a result, reading from an undefined address takes place.

Отчет

The described vulnerability in the keepalived package, characterized by an integer overflow in the vrrp_ipsets_handler function of fglobal_parser.c, is assessed as moderate severity rather than important due to the specific conditions required for exploitation. The flaw necessitates the manual configuration of an empty ipset name, a scenario that deviates from standard operational procedures. This constraint significantly reduces the likelihood of the vulnerability being exploited in typical deployment environments. Additionally, the primary consequence of this integer overflow is reading from an undefined address, which, while potentially disruptive, is less severe compared to vulnerabilities that allow arbitrary code execution or privilege escalation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 5rhceph/keepalived-rhel8Out of support scope
Red Hat Ceph Storage 6rhceph/keepalived-rhel9Affected
Red Hat Ceph Storage 7rhceph/keepalived-rhel9Affected
Red Hat Enterprise Linux 10keepalivedAffected
Red Hat Enterprise Linux 7keepalivedOut of support scope
Red Hat Enterprise Linux 8keepalivedFixedRHSA-2025:074328.01.2025
Red Hat Enterprise Linux 9keepalivedFixedRHSA-2025:091704.02.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2298532keepalived: Integer overflow vulnerability in vrrp_ipsets_handler

EPSS

Процентиль: 50%
0.00269
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
11 месяцев назад

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

CVSS3: 9.8
nvd
11 месяцев назад

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

CVSS3: 9.8
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 9.8
debian
11 месяцев назад

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived th ...

suse-cvrf
8 месяцев назад

Security update for keepalived

EPSS

Процентиль: 50%
0.00269
Низкий

6.3 Medium

CVSS3