CVE-2021-45951
Description
De CVE.org
Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckForBogusWildcard). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.
Déclaration
Red Hat Product Security does not consider this to be a vulnerability.
Détails du score du système commun d'évaluation des vulnérabilités (CVSS)
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
Les mesures et les scores CVSS suivants sont préliminaires et sujets à révision.
Répartition des scores CVSS v3
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Score de base | 0 | 9.8 | N/A |
| Vecteur d'attaque | Network | Network | N/A |
| Complexité de l'attaque | Low | Low | N/A |
| Privilèges requis | None | None | N/A |
| Interaction avec l'utilisateur | None | None | N/A |
| Champ d'application | Unchanged | Unchanged | N/A |
| Confidentialité | None | High | N/A |
| Impact sur l'intégrité | None | High | N/A |
| Impact sur la disponibilité | None | High | N/A |
Vecteur
Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Explication du score CVSS v3 de Red Hat
Red Hat Product Security does not consider this to be a vulnerability.
Comprendre la Défaillance (CWE)
Integrity
Technical Impact: Modify Memory; Execute Unauthorized Code or Commands
Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash.
Other
Technical Impact: Unexpected State
Subsequent write operations can produce undefined or unexpected results.
Questions fréquemment posées
Not sure what something means? Check out our Security Glossary.
Vous souhaitez recevoir des notifications d'errata ? Signez ici.