Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-32166

Опубликовано: 28 сент. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 6.1

Описание

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

РелизСтатусПримечание
bionic

released

2.9.8-0ubuntu0.18.04.3
devel

not-affected

3.0.0-0ubuntu1
esm-infra/bionic

released

2.9.8-0ubuntu0.18.04.3
esm-infra/focal

not-affected

2.13.8-0ubuntu1
esm-infra/xenial

released

2.5.9-0ubuntu0.16.04.3+esm1
focal

not-affected

2.13.8-0ubuntu1
jammy

not-affected

2.17.2-0ubuntu0.22.04.1
kinetic

not-affected

3.0.0-0ubuntu1
trusty

ignored

end of standard support
upstream

needs-triage

Показывать по

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.6
redhat
больше 3 лет назад

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

CVSS3: 6.1
nvd
больше 3 лет назад

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

CVSS3: 6.1
debian
больше 3 лет назад

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer o ...

suse-cvrf
около 3 лет назад

Security update for openvswitch

CVSS3: 8.8
github
больше 3 лет назад

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

6.1 Medium

CVSS3