Логотип exploitDog
bind:CVE-2019-18609
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-18609

Количество 8

Количество 8

ubuntu логотип

CVE-2019-18609

около 6 лет назад

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2019-18609

около 6 лет назад

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2019-18609

около 6 лет назад

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-18609

около 6 лет назад

An issue was discovered in amqp_handle_input in amqp_connection.c in r ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-356h-gg7j-mwv3

больше 3 лет назад

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

EPSS: Низкий
oracle-oval логотип

ELSA-2020-4445

около 5 лет назад

ELSA-2020-4445: librabbitmq security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-3949

больше 5 лет назад

ELSA-2020-3949: librabbitmq security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2022-05699

больше 6 лет назад

Уязвимость функции amqp_handle_input компонента amqp_connection.c брокера сообщений RabbitMQ, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-18609

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

CVSS3: 9.8
3%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-18609

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

CVSS3: 8.6
3%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-18609

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

CVSS3: 9.8
3%
Низкий
около 6 лет назад
debian логотип
CVE-2019-18609

An issue was discovered in amqp_handle_input in amqp_connection.c in r ...

CVSS3: 9.8
3%
Низкий
около 6 лет назад
github логотип
GHSA-356h-gg7j-mwv3

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

3%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2020-4445

ELSA-2020-4445: librabbitmq security update (MODERATE)

около 5 лет назад
oracle-oval логотип
ELSA-2020-3949

ELSA-2020-3949: librabbitmq security update (MODERATE)

больше 5 лет назад
fstec логотип
BDU:2022-05699

Уязвимость функции amqp_handle_input компонента amqp_connection.c брокера сообщений RabbitMQ, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 9.8
3%
Низкий
больше 6 лет назад

Уязвимостей на страницу