Количество 11
Количество 11
BDU:2025-11746
Уязвимость DHCP-сервера с открытым исходным кодом Kea, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю получить доступ на запись произвольных файлов
ROS-20250924-05
Множественные уязвимости kea
CVE-2025-32802
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.
CVE-2025-32802
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.
CVE-2025-32802
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.
CVE-2025-32802
Kea configuration and API directives can be used to overwrite arbitrar ...
GHSA-vwc9-wh34-hrfm
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.
SUSE-SU-2026:1091-1
Security update for kea
SUSE-SU-2026:0907-1
Security update for kea
RLSA-2025:9178
Important: kea security update
ELSA-2025-9178
ELSA-2025-9178: kea security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2025-11746 Уязвимость DHCP-сервера с открытым исходным кодом Kea, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю получить доступ на запись произвольных файлов | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
ROS-20250924-05 Множественные уязвимости kea | CVSS3: 6.1 | около 1 года назад | ||
CVE-2025-32802 Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
CVE-2025-32802 Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
CVE-2025-32802 Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
CVE-2025-32802 Kea configuration and API directives can be used to overwrite arbitrar ... | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-vwc9-wh34-hrfm Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
SUSE-SU-2026:1091-1 Security update for kea | 6 месяцев назад | |||
SUSE-SU-2026:0907-1 Security update for kea | 6 месяцев назад | |||
RLSA-2025:9178 Important: kea security update | 12 месяцев назад | |||
ELSA-2025-9178 ELSA-2025-9178: kea security update (IMPORTANT) | больше 1 года назад |
Уязвимостей на страницу