Описание
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | not-affected | 1.41-3 |
| esm-apps/bionic | released | 1.35-6ubuntu0.1~esm1 |
| esm-apps/focal | released | 1.36-2ubuntu0.1 |
| esm-apps/jammy | released | 1.36-2.3ubuntu0.1 |
| esm-apps/xenial | released | 1.21-1.2+deb8u1ubuntu0.1~esm1 |
| focal | released | 1.36-2ubuntu0.1 |
| jammy | released | 1.36-2.3ubuntu0.1 |
| kinetic | not-affected | 1.41-2 |
| lunar | not-affected | 1.41-2 |
Показывать по
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.
In ConnMan through 1.41, remote attackers able to send HTTP requests t ...
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.
Уязвимость компонента gweb диспетчера соединений Connman, связанная с записью за границами выделенного диапазона памяти, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3