Lucene search

K
redosRedosROS-20240805-08
HistoryAug 05, 2024 - 12:00 a.m.

ROS-20240805-08

2024-08-0500:00:00
redos.red-soft.ru
7
vulnerabilities
golang
debian gnu/linux
operating system
protection
exception handling
infinite loop
remote attacker
denial of service
golang-google-protobuf
programming language
libexpat
xml
file parsing
uncontrolled resource consumption
html/template
input validation
arbitrary content

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.9

Confidence

High

A vulnerability in the golang package of the Debian GNU/Linux operating system is related to a lack of protection for service data.
data. Exploitation of the vulnerability could allow an attacker acting remotely to gain access to
sensitive information

A vulnerability in the golang package of the Debian GNU/Linux operating system is related to an exception handling flaw.
exceptions. Exploitation of the vulnerability could allow a remote attacker to cause a denial of service (DoS).
denial of service (DoS)

A vulnerability in the protojson.Unmarshal() function of the golang-google-protobuf package of the Golang programming language
is related to an infinite loop when anmarshaling certain JSON forms. Exploitation of the vulnerability could
allow an attacker acting remotely to cause a denial of service

A vulnerability in the libexpat XML file parsing library is related to improper restriction of recursive
references to objects in DTDs. Exploitation of the vulnerability could allow an attacker to cause a denial of service

A vulnerability in the golang package of the Debian GNU/Linux operating system is related to uncontrolled resource consumption.
resources. Exploitation of the vulnerability could allow an attacker acting remotely to cause a denial of service (DoS).
denial of service (DoS)

Vulnerability in the XML parser library libexpat is associated with an uncontrolled resource drain.
resources. Exploitation of the vulnerability could allow an attacker acting remotely to cause a denial of service (DoS).
denial of service

A vulnerability in the html/template package of the Go programming language is related to a lack of input validation.
values. Exploitation of the vulnerability could allow an attacker acting remotely to inject
arbitrary content into templates

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64consul< 1.18.2-1UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.9

Confidence

High