Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-5243

Опубликовано: 21 фев. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 5.7

Описание

uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This has been patched in uap-core 0.7.3.

РелизСтатусПримечание
bionic

DNE

devel

needed

eoan

ignored

end of life
esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needed
groovy

ignored

end of life
hirsute

ignored

end of life

Показывать по

EPSS

Процентиль: 74%
0.00805
Низкий

5 Medium

CVSS2

5.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
nvd
почти 6 лет назад

uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This has been patched in uap-core 0.7.3.

CVSS3: 5.7
debian
почти 6 лет назад

uap-core before 0.7.3 is vulnerable to a denial of service attack when ...

CVSS3: 5.7
github
почти 6 лет назад

Denial of Service in uap-core when processing crafted User-Agent strings

EPSS

Процентиль: 74%
0.00805
Низкий

5 Medium

CVSS2

5.7 Medium

CVSS3