Описание
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
Меры по смягчению последствий
If AirPlay streaming is not required, unload or disable the module-raop-discover and module-raop-sink PipeWire modules.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libkrun | Under investigation | ||
| Red Hat Enterprise Linux 10 | pipewire | Under investigation | ||
| Red Hat Enterprise Linux 8 | pipewire | Under investigation | ||
| Red Hat Enterprise Linux 8 | pipewire0.2 | Under investigation | ||
| Red Hat Enterprise Linux 9 | pipewire | Under investigation |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2495903pipewire: RAOP RTSP NULL Deref
EPSS
Процентиль: 7%
0.00175
Низкий
6.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.5
ubuntu
около 2 месяцев назад
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
CVSS3: 6.5
nvd
около 2 месяцев назад
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
CVSS3: 6.5
debian
около 2 месяцев назад
RAOP module accepts unbounded Content-Length values and does not check ...
CVSS3: 6.5
github
около 2 месяцев назад
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
EPSS
Процентиль: 7%
0.00175
Низкий
6.5 Medium
CVSS3