Lucene search

K
cve[email protected]CVE-2010-2725
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-2725

2022-10-0316:21:07
CWE-20
web.nvd.nist.gov
36
cve-2010-2725
barnowl
denial of service
libzephyr
remote attackers
arbitrary code
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

79.9%

BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

Affected configurations

NVD
Node
barnowlbarnowlRange≤1.6.1
OR
barnowlbarnowlMatch1.0.0
OR
barnowlbarnowlMatch1.0.1
OR
barnowlbarnowlMatch1.0.2
OR
barnowlbarnowlMatch1.0.2.1
OR
barnowlbarnowlMatch1.0.3
OR
barnowlbarnowlMatch1.0.4
OR
barnowlbarnowlMatch1.0.4.1
OR
barnowlbarnowlMatch1.0.5
OR
barnowlbarnowlMatch1.1
OR
barnowlbarnowlMatch1.1.1
OR
barnowlbarnowlMatch1.2
OR
barnowlbarnowlMatch1.2.1
OR
barnowlbarnowlMatch1.3
OR
barnowlbarnowlMatch1.4
OR
barnowlbarnowlMatch1.4rc1
OR
barnowlbarnowlMatch1.5
OR
barnowlbarnowlMatch1.5rc1
OR
barnowlbarnowlMatch1.5rc2
OR
barnowlbarnowlMatch1.5.1
OR
barnowlbarnowlMatch1.6

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

79.9%