Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-19115

Опубликовано: 08 нояб. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.

РелизСтатусПримечание
bionic

released

1:1.3.9-1ubuntu0.18.04.2
cosmic

released

1:1.3.9-1ubuntu1.1
devel

not-affected

1:2.0.10-1
disco

not-affected

1:2.0.10-1
esm-infra-legacy/trusty

released

1:1.2.7-1ubuntu1+esm1
esm-infra/bionic

released

1:1.3.9-1ubuntu0.18.04.2
esm-infra/xenial

released

1:1.2.24-1ubuntu0.16.04.2
precise/esm

not-affected

1:1.2.2-3ubuntu1.2
trusty

ignored

end of standard support
trusty/esm

released

1:1.2.7-1ubuntu1+esm1

Показывать по

EPSS

Процентиль: 90%
0.06203
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
около 7 лет назад

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.

CVSS3: 9.8
nvd
около 7 лет назад

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.

CVSS3: 9.8
debian
около 7 лет назад

keepalived before 2.0.7 has a heap-based buffer overflow when parsing ...

CVSS3: 9.8
github
больше 3 лет назад

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.

oracle-oval
почти 7 лет назад

ELSA-2019-0022: keepalived security update (IMPORTANT)

EPSS

Процентиль: 90%
0.06203
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3