Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-31348

Опубликовано: 16 апр. 2021
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.5

Описание

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

needed

esm-apps-legacy/xenial

ignored

will not be fixed upstream
esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/resolute

needed

esm-apps/xenial

ignored

end of ESM support, was ignored [will not be fixed upstream]
esm-infra-legacy/trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1:4.9.3-1build1
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/focal

ignored

changes too intrusive
esm-apps/jammy

ignored

changes too intrusive
esm-apps/noble

not-affected

1:4.9.2-5ubuntu4
esm-apps/resolute

not-affected

1:4.9.3-1build1
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

1:4.9.3-2build2
esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/resolute

needed

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needed
groovy

ignored

end of life
hirsute

ignored

end of life

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

needed

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/resolute

needed

esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

DNE

Показывать по

Ссылки на источники

EPSS

Процентиль: 63%
0.01095
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).

CVSS3: 6.5
debian
больше 5 лет назад

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezx ...

CVSS3: 6.5
github
больше 4 лет назад

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).

CVSS3: 6.5
fstec
больше 5 лет назад

Уязвимость функции ezxml_parse_str библиотеки для синтаксического анализа XML-документов ezXML, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
больше 4 лет назад

Security update for netcdf

EPSS

Процентиль: 63%
0.01095
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Уязвимость CVE-2021-31348