Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-31348

Опубликовано: 16 апр. 2021
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.5

Описание

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

needed

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/xenial

ignored

will not be fixed upstream
esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needed
groovy

ignored

end of life

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1:4.9.3-1build1
esm-apps/bionic

not-affected

code not present
esm-apps/focal

ignored

changes too intrusive
esm-apps/jammy

ignored

changes too intrusive
esm-apps/noble

not-affected

1:4.9.2-5ubuntu4
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
focal

ignored

end of standard support, was ignored [changes too intrusive]
groovy

ignored

end of life

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needed
groovy

ignored

end of life
hirsute

ignored

end of life
impish

ignored

end of life

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

needed

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needed
groovy

ignored

end of life

Показывать по

Ссылки на источники

EPSS

Процентиль: 75%
0.00858
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 5 лет назад

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).

CVSS3: 6.5
debian
почти 5 лет назад

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezx ...

CVSS3: 6.5
github
больше 3 лет назад

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).

CVSS3: 6.5
fstec
почти 5 лет назад

Уязвимость функции ezxml_parse_str библиотеки для синтаксического анализа XML-документов ezXML, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
около 4 лет назад

Security update for netcdf

EPSS

Процентиль: 75%
0.00858
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3