6.8
CVE-2021-3672
- EPSS 2.6%
- Veröffentlicht 23.11.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:07
- Erkennungen
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
C-ares Project ≫ C-ares Version >= 1.0.0 < 1.17.2
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 7.7
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Computer Node Version 1
Redhat ≫ Enterprise Linux Eus Version 7.7
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 8.0
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.1
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.2
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.4
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.1
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.2
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.4
Redhat ≫ Enterprise Linux Server Aus Version 8.2
Redhat ≫ Enterprise Linux Server Aus Version 8.4
Redhat ≫ Enterprise Linux Server Tus Version 8.2
Redhat ≫ Enterprise Linux Server Tus Version 8.4
Redhat ≫ Enterprise Linux Tus Version 8.4
Redhat ≫ Enterprise Linux Workstation Version 1
Siemens ≫ Sinec Infrastructure Network Services Version < 1.0.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.6% | 0.838 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.6 | 2.2 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://www.oracle.com/security-alerts/cpujul2022.html
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
https://security.gentoo.org/glsa/202401-02
https://bugzilla.redhat.com/show_bug.cgi?id=1988342
https://c-ares.haxx.se/adv_20210810.html