Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-30211

Опубликовано: 28 мар. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in KEX init message. Big KEX init packet may lead to inefficient processing of the error data. As a result, large amount of memory will be allocated for processing malicious data. Versions OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19 fix the issue. Some workarounds are available. One may set option parallel_login to false and/or reduce the max_sessions option.

РелизСтатусПримечание
devel

released

1:27.3+dfsg-1ubuntu1
esm-infra-legacy/trusty

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

not-affected

1:22.2.7+dfsg-1ubuntu0.4
esm-infra/xenial

needs-triage

focal

released

1:22.2.7+dfsg-1ubuntu0.4
jammy

released

1:24.2.1+dfsg-1ubuntu0.3
noble

released

1:25.3.2.8+dfsg-1ubuntu4.2
oracular

released

1:25.3.2.12+dfsg-1ubuntu2.2
plucky

released

1:27.3+dfsg-1ubuntu1

Показывать по

EPSS

Процентиль: 23%
0.00074
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
3 месяца назад

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in KEX init message. Big KEX init packet may lead to inefficient processing of the error data. As a result, large amount of memory will be allocated for processing malicious data. Versions OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19 fix the issue. Some workarounds are available. One may set option `parallel_login` to `false` and/or reduce the `max_sessions` option.

CVSS3: 7.5
nvd
3 месяца назад

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in KEX init message. Big KEX init packet may lead to inefficient processing of the error data. As a result, large amount of memory will be allocated for processing malicious data. Versions OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19 fix the issue. Some workarounds are available. One may set option `parallel_login` to `false` and/or reduce the `max_sessions` option.

CVSS3: 7.5
msrc
2 месяца назад

Описание отсутствует

CVSS3: 7.5
debian
3 месяца назад

Erlang/OTP is a set of libraries for the Erlang programming language. ...

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость набора библиотек OTP языка программирования Erlang, связанная с отсутсвием контроля вводимых пользователем данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 23%
0.00074
Низкий

7.5 High

CVSS3