Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-5564

Опубликовано: 31 мая 2024
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.

Отчет

Red Hat rates this as an Important severity, as a local attacker may gain enough information to jeopardize the environment's confidentiality, integrity and availability.

Меры по смягчению последствий

Currently there is no mitigation available for this vulnerability. Please make sure to update as the fixes become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libndpAffected
Red Hat Enterprise Linux 7 Extended Lifecycle SupportlibndpFixedRHSA-2024:462218.07.2024
Red Hat Enterprise Linux 8libndpFixedRHSA-2024:462018.07.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportlibndpFixedRHSA-2024:464018.07.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibndpFixedRHSA-2024:461818.07.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicelibndpFixedRHSA-2024:461818.07.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionslibndpFixedRHSA-2024:461818.07.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportlibndpFixedRHSA-2024:464318.07.2024
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicelibndpFixedRHSA-2024:464318.07.2024
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionslibndpFixedRHSA-2024:464318.07.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2284122libndp: buffer overflow in route information length field

EPSS

Процентиль: 80%
0.01475
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 года назад

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.

CVSS3: 8.1
nvd
около 1 года назад

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.

CVSS3: 8.1
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 8.1
debian
около 1 года назад

A vulnerability was found in libndp. This flaw allows a local maliciou ...

suse-cvrf
11 месяцев назад

Security update for libndp

EPSS

Процентиль: 80%
0.01475
Низкий

8.1 High

CVSS3

Уязвимость CVE-2024-5564