Lucene search

K
redosRedosROS-20220914-01
HistorySep 14, 2022 - 12:00 a.m.

ROS-20220914-01

2022-09-1400:00:00
redos.red-soft.ru
6
vulnerability
libconfuse
buffer overflow
denial of service
remote attackers
unix

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.9%

A vulnerability in the libConfuse configuration file parser library is related to a buffer overflow in the function
cfg_tilde_expand in confuse.c. Exploitation of the vulnerability could allow an attacker acting remotely,
transmit a specially crafted file to the system, causing a buffer overflow and denial of service

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64libconfuse< 3.3-3UNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.9%