Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-5564

Опубликовано: 31 мая 2024
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.

Отчет

Red Hat rates this as an Important severity, as a local attacker may gain enough information to jeopardize the environment's confidentiality, integrity and availability.

Меры по смягчению последствий

Currently there is no mitigation available for this vulnerability. Please make sure to update as the fixes become available.

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2284122libndp: buffer overflow in route information length field

EPSS

Процентиль: 73%
0.00801
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 года назад

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.

CVSS3: 8.1
nvd
около 1 года назад

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.

CVSS3: 8.1
msrc
около 1 года назад

Описание отсутствует

CVSS3: 8.1
debian
около 1 года назад

A vulnerability was found in libndp. This flaw allows a local maliciou ...

suse-cvrf
около 1 года назад

Security update for libndp

EPSS

Процентиль: 73%
0.00801
Низкий

8.1 High

CVSS3