Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-30211

Опубликовано: 28 мар. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in KEX init message. Big KEX init packet may lead to inefficient processing of the error data. As a result, large amount of memory will be allocated for processing malicious data. Versions OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19 fix the issue. Some workarounds are available. One may set option parallel_login to false and/or reduce the max_sessions option.

РелизСтатусПримечание
devel

released

1:27.3+dfsg-1ubuntu1
esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

released

1:22.2.7+dfsg-1ubuntu0.4
esm-infra/xenial

ignored

end of ESM support, was needs-triage
focal

released

1:22.2.7+dfsg-1ubuntu0.4
jammy

released

1:24.2.1+dfsg-1ubuntu0.3
noble

released

1:25.3.2.8+dfsg-1ubuntu4.2
oracular

released

1:25.3.2.12+dfsg-1ubuntu2.2

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 1 года назад

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in KEX init message. Big KEX init packet may lead to inefficient processing of the error data. As a result, large amount of memory will be allocated for processing malicious data. Versions OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19 fix the issue. Some workarounds are available. One may set option `parallel_login` to `false` and/or reduce the `max_sessions` option.

CVSS3: 7.5
nvd
больше 1 года назад

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in KEX init message. Big KEX init packet may lead to inefficient processing of the error data. As a result, large amount of memory will be allocated for processing malicious data. Versions OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19 fix the issue. Some workarounds are available. One may set option `parallel_login` to `false` and/or reduce the `max_sessions` option.

CVSS3: 7.5
msrc
больше 1 года назад

KEX init error results with excessive memory usage

CVSS3: 7.5
debian
больше 1 года назад

Erlang/OTP is a set of libraries for the Erlang programming language. ...

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость набора библиотек OTP языка программирования Erlang, связанная с отсутсвием контроля вводимых пользователем данных, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3