Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-5704

Опубликовано: 16 янв. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 9.3
CVSS3: 9.6

Описание

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

0.10.0-4
cosmic

not-affected

0.10.0-4
devel

not-affected

0.10.0-4
disco

not-affected

0.10.0-4
esm-apps/bionic

not-affected

0.10.0-4
esm-apps/xenial

released

0.9.0-1+deb8u1build0.16.04.1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
precise/esm

DNE

trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 83%
0.0189
Низкий

9.3 Critical

CVSS2

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
nvd
около 8 лет назад

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

CVSS3: 9.6
debian
около 8 лет назад

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use ...

CVSS3: 9.6
github
больше 3 лет назад

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

EPSS

Процентиль: 83%
0.0189
Низкий

9.3 Critical

CVSS2

9.6 Critical

CVSS3