Lucene search

K
cloudlinuxCloudLinuxCLSA-2021:1637673150
HistoryNov 23, 2021 - 1:12 p.m.

Fix of CVE: CVE-2021-3903, CVE-2021-3875, CVE-2021-3872

2021-11-2313:12:30
repo.cloudlinux.com
31
cve-2021-3903
invalid memory access
cve-2021-3875
range search error
cve-2021-3872
buffer overflow fix
unix

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

49.5%

  • CVE-2021-3872: fix illegal memory access if buffer name is very long
  • CVE-2021-3875: fix ml_get error after search with range
  • CVE-2021-3903: fix invalid memory access when scrolling without a valid screen

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

49.5%