8.3

CVE-2020-14305

Exploit
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 4.11.12
Linux ≫ Linux Kernel Version 4.12 Update -
Netapp ≫ Cloud Backup Version -
Netapp ≫ A250 Firmware Version -
   Netapp ≫ A250 Version -
Netapp ≫ Fas 500f Firmware Version -
   Netapp ≫ Fas 500f Version -
Netapp ≫ Aff 500f Firmware Version -
   Netapp ≫ Aff 500f Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.11% 0.913
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 8.3 8.6 8.5
AV:N/AC:M/Au:N/C:P/I:P/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://bugs.openvz.org/browse/OVZ-7188
Third Party Advisory
Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=1850716
Patch
Third Party Advisory
Issue Tracking
https://patchwork.ozlabs.org/project/netfilter-devel/patch/c2385b5c-309c-cc64-2e10-a0ef62897502%40virtuozzo.com/
https://security.netapp.com/advisory/ntap-20201210-0004/
Third Party Advisory