PT-2018-2889 · Red Hat+2 · Cockpit+3

Pedro Sampaio

·

Published

2018-11-13

·

Updated

2022-11-07

·

CVE-2019-3804

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cockpit versions prior to 184
Description The issue is caused by a buffer overflow in memory due to incorrect use of glib's base64 decode functionality. This can be exploited by a remote attacker using a specially crafted request with an invalid base64-encoded cookie, potentially leading to a denial of service.
Recommendations For versions prior to 184, update to version 184 or later to resolve the issue. As a temporary workaround, consider restricting access to the web service to minimize the risk of exploitation.

Fix

DoS

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1072
BDU:2019-02448
CESA-2019_0482
CVE-2019-3804
RHSA-2019:0482
RHSA-2019:1569
RHSA-2019:1571
RHSA-2019_0482

Affected Products

Alt Linux
Centos
Cockpit
Red Hat