BDU:2017-00285HighConfirmedExploit available
BDU
BDU
Data Bank of Information Security Threats
BDU ФСТЭК is the authoritative Russian source of vulnerability information, covering both international CVEs relevant to domestic software and unique Russian-disclosed issues. Entries contain severity, affected product lists (in Russian), and mitigation recommendations.
Region
RU
Updates
1 ч
License
Открытые данные
Russian federal catalog of vulnerabilities and threats maintained by FSTEC. Required for compliance with Russian information security regulations (Приказ №17, Приказ №21).
https://bdu.fstec.ru →Share link
Anyone with the link can open this vulnerability.
Уязвимость функции encode_name (misc/mntent_r.c) библиотеки, обеспечивающей системные вызовы и основные функции glibc существует из-за ошиб…
CVSS
7.2
High
EPSS
0.00
p0
Published
2017-01-01
Updated
2017-01-01
Description
Уязвимость функции encode_name (misc/mntent_r.c) библиотеки, обеспечивающей системные вызовы и основные функции glibc существует из-за ошибок при обработке символов новой строки в именах точек монтирования при использовании ncpmount и mount.cifs. Эксплуатация уязвимости может позволить нарушителю, действующему локально, вызвать отказ в обслуживании или повысить свои привилегии при помощи специально сформированного запроса на монтирование каталога
Affected products
Huawei technologies co., ltd. Usg6330The gnu project Glibc
CVSS vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
15274
exploitdb · https://www.exploit-db.com/exploits/15274
15304
exploitdb · https://www.exploit-db.com/exploits/15304
17120
exploitdb · https://www.exploit-db.com/exploits/17120
18105
exploitdb · https://www.exploit-db.com/exploits/18105
31550
exploitdb · https://www.exploit-db.com/exploits/31550
33230
exploitdb · https://www.exploit-db.com/exploits/33230
36404
exploitdb · https://www.exploit-db.com/exploits/36404
44024
exploitdb · https://www.exploit-db.com/exploits/44024
44025
exploitdb · https://www.exploit-db.com/exploits/44025
CVE-2010-3847
github-poc · https://github.com/magisterquis/cve-2010-3847
Affected software
| Product | Vendor | Status |
|---|---|---|
| usg6330 | huawei technologies co., ltd. | Tracked |
| glibc | the gnu project | Tracked |
Source databases
BDU
BDU
Data Bank of Information Security Threats
BDU ФСТЭК is the authoritative Russian source of vulnerability information, covering both international CVEs relevant to domestic software and unique Russian-disclosed issues. Entries contain severity, affected product lists (in Russian), and mitigation recommendations.
Region
RU
Updates
1 ч
License
Открытые данные
Russian federal catalog of vulnerabilities and threats maintained by FSTEC. Required for compliance with Russian information security regulations (Приказ №17, Приказ №21).
https://bdu.fstec.ru →Related vulnerabilities