Описание
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 1:27.3.4.3+dfsg-1 |
| esm-infra-legacy/trusty | released | 1:16.b.3-dfsg-1ubuntu2.2+esm1 |
| esm-infra-legacy/xenial | released | 1:18.3-dfsg-1ubuntu3.1+esm2 |
| esm-infra/bionic | released | 1:20.2.2+dfsg-1ubuntu2+esm2 |
| esm-infra/focal | released | 1:22.2.7+dfsg-1ubuntu0.5+esm1 |
| esm-infra/xenial | released | 1:18.3-dfsg-1ubuntu3.1+esm2 |
| jammy | released | 1:24.2.1+dfsg-1ubuntu0.6 |
| noble | released | 1:25.3.2.8+dfsg-1ubuntu4.5 |
| plucky | released | 1:27.3+dfsg-1ubuntu1.3 |
| questing | released | 1:27.3.4.1+dfsg-1ubuntu0.1 |
Показывать по
Связанные уязвимости
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.
Unverified Paths can Cause Excessive Use of System Resources
Allocation of Resources Without Limits or Throttling vulnerability in ...
Уязвимость набора библиотек OTP языка программирования Erlang, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании