Lucene search

K
freebsdFreeBSD0167F5AD-64EA-11E4-98C1-00269EE29E57
HistoryNov 04, 2014 - 12:00 a.m.

Konversation -- out-of-bounds read on a heap-allocated array

2014-11-0400:00:00
vuxml.freebsd.org
11

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.034 Low

EPSS

Percentile

91.5%

Konversation developers report:

Konversation’s Blowfish ECB encryption support assumes incoming blocks
to be the expected 12 bytes. The lack of a sanity-check for the actual
size can cause a denial of service and an information leak to the local
user.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchkonversation< 1.5.1UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.034 Low

EPSS

Percentile

91.5%