Lucene search

K
redosRedosROS-20231016-05
HistoryOct 16, 2023 - 12:00 a.m.

ROS-20231016-05

2023-10-1600:00:00
redos.red-soft.ru
20
vulnerability
curl
libcurl
remote attacker
denial of service
arbitrary cookies
unix

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.7%

A vulnerability in the curl program line utility is related to a copy of the hostname in the buffer instead of the allowed
address. Exploitation of the vulnerability could allow an attacker acting remotely to cause a denial of
denial of service

A vulnerability in the libcurl library is related to inserting cookies into a running program. Exploitation
exploitation of this vulnerability could allow a remote attacker to load arbitrary cookies.

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64curl<= 7.85.0-15UNKNOWN

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.7%