ALT-PU-2020-3186-1
Closed vulnerabilities
Published: 2016-02-04
BDU:2018-00035
Уязвимость функции queue_push (queue/queuepush.c) пакета yodl, позволяющая нарушителю нарушить конфиденциальность, целостность и доступность данных
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2017-05-26
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-10375
Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c.
Severity: CRITICAL (9.8)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- https://github.com/fbb-git/yodl/commit/fd85f8c94182558ff1480d06a236d6fb927979a3
- https://github.com/fbb-git/yodl/commit/fd85f8c94182558ff1480d06a236d6fb927979a3
- https://github.com/fbb-git/yodl/issues/1
- https://github.com/fbb-git/yodl/issues/1
- [debian-lts-announce] 20200430 [SECURITY] [DLA 2194-1] yodl security update
- [debian-lts-announce] 20200430 [SECURITY] [DLA 2194-1] yodl security update