[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2021-3570Date: (C)2021-07-10   (M)2024-01-05


A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This flaw affects linuxptp versions before 3.1.1, before 2.0.1, before 1.9.3, before 1.8.1, before 1.7.1, before 1.6.1 and before 1.5.1.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.8CVSS Score : 8.0
Exploit Score: 2.8Exploit Score: 8.0
Impact Score: 5.9Impact Score: 8.5
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: SINGLE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: COMPLETE
Integrity: HIGH 
Availability: HIGH 
  
Reference:
DSA-4938
FEDORA-2021-1b42c2f458
FEDORA-2021-a5b584004c
https://lists.debian.org/debian-lts-announce/2021/07/msg00025.html
https://bugzilla.redhat.com/show_bug.cgi?id=1966240

CPE    1
cpe:/o:redhat:enterprise_linux:7.0
CWE    1
CWE-787
OVAL    19
oval:org.secpod.oval:def:506242
oval:org.secpod.oval:def:506244
oval:org.secpod.oval:def:89045491
oval:org.secpod.oval:def:89045493
...

© SecPod Technologies