Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-11678

Опубликовано: 20 окт. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.

РелизСтатусПримечание
devel

not-affected

4.3.5-3
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

released

4.0.20-2ubuntu1.1
esm-apps/noble

released

4.3.3-1.1ubuntu0.1~esm1
esm-apps/resolute

not-affected

4.3.5-3
esm-apps/xenial

not-affected

code not present
jammy

released

4.0.20-2ubuntu1.1
noble

needed

Показывать по

EPSS

Процентиль: 18%
0.00266
Низкий

Связанные уязвимости

CVSS3: 7.6
redhat
9 месяцев назад

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.

nvd
9 месяцев назад

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.

debian
9 месяцев назад

Stack-based Buffer Overflowin lws_adns_parse_label in warmcat libwebso ...

github
9 месяцев назад

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.

EPSS

Процентиль: 18%
0.00266
Низкий