CVE-2020-6750

説明

CVE.org より

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.

詳細

As per upstream versions of glib2 before 2.60 are unaffected, therefore glib2 package shipped with Red Hat Products are not affected by this flaw.

CVSS (Common Vulnerability Scoring System) のスコアの詳細

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

以下の CSVV メトリクスおよびスコアは予備的で、再検討の対象となります。

CVSS v3 スコアの内訳

Red HatNVDcve.org
ベーススコア6.85.9N/A
攻撃ベクトルNetworkNetworkN/A
攻撃の複雑さHighHighN/A
必要な権限NoneNoneN/A
ユーザー関与レベルRequiredNoneN/A
範囲UnchangedUnchangedN/A
機密性HighHighN/A
完全性への影響HighNoneN/A
可用性への影響NoneNoneN/A

ベクトル

Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

NVD: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

脆弱性の原因 (CWE) の理解

Availability

Technical Impact: DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory)

An attacker could provide unexpected values and cause a program crash or arbitrary control of resource allocation, leading to excessive consumption of resources such as memory and CPU.

Confidentiality

Technical Impact: Read Memory; Read Files or Directories

An attacker could read confidential data if they are able to control resource references.

Integrity,Confidentiality,Availability

Technical Impact: Modify Memory; Execute Unauthorized Code or Commands

An attacker could use malicious input to modify data or possibly alter control flow in unexpected ways, including arbitrary command execution.

よくある質問

エラータ通知の受信を希望しますか? こちらで登録してください。