Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13194
HistoryJan 15, 2019 - 9:27 a.m.

Denial Of Service (DoS)

2019-01-1509:27:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.013 Low

EPSS

Percentile

85.9%

keepalived is vulnerable to denial of service. A lack of validation of HTTP status codes in the extract_status_code function in lib/html.c results in a heap-based buffer overflow when parsing malicious HTTP status codes, allowing a remote attacker to crash the daemon, or possibly execute arbitrary code.

CPENameOperatorVersion
keepalivedeq1.3.5__6.el7