Логотип exploitDog
bind:"BDU:2022-07496" OR bind:"CVE-2022-36227"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2022-07496" OR bind:"CVE-2022-36227"

Количество 13

Количество 13

fstec логотип

BDU:2022-07496

около 3 лет назад

Уязвимость функции calloc() библиотеки архивирования libarchive, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2022-36227

почти 3 года назад

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-36227

около 3 лет назад

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2022-36227

почти 3 года назад

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2022-36227

почти 3 года назад

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-36227

почти 3 года назад

In libarchive before 3.6.2, the software does not check for an error a ...

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4296-1

почти 3 года назад

Security update for libarchive

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4209-1

почти 3 года назад

Security update for libarchive

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4202-1

почти 3 года назад

Security update for libarchive

EPSS: Низкий
redos логотип

ROS-20221216-01

больше 2 лет назад

Уязвимость libarchive

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-gpgf-w78r-4pvj

почти 3 года назад

In libarchive 3.6.1, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference or, in some cases, even arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
oracle-oval логотип

ELSA-2023-3018

больше 2 лет назад

ELSA-2023-3018: libarchive security update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-2532

больше 2 лет назад

ELSA-2023-2532: libarchive security update (LOW)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2022-07496

Уязвимость функции calloc() библиотеки архивирования libarchive, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 9.8
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-36227

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."

CVSS3: 9.8
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-36227

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."

CVSS3: 5.9
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-36227

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."

CVSS3: 9.8
0%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 9.8
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-36227

In libarchive before 3.6.2, the software does not check for an error a ...

CVSS3: 9.8
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:4296-1

Security update for libarchive

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:4209-1

Security update for libarchive

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:4202-1

Security update for libarchive

0%
Низкий
почти 3 года назад
redos логотип
ROS-20221216-01

Уязвимость libarchive

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-gpgf-w78r-4pvj

In libarchive 3.6.1, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference or, in some cases, even arbitrary code execution.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
oracle-oval логотип
ELSA-2023-3018

ELSA-2023-3018: libarchive security update (LOW)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-2532

ELSA-2023-2532: libarchive security update (LOW)

больше 2 лет назад

Уязвимостей на страницу