PT-2018-2889 · Red Hat+2 · Cockpit+3
Pedro Sampaio
·
Published
2018-11-13
·
Updated
2022-11-07
·
CVE-2019-3804
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cockpit versions prior to 184
Description
The issue is caused by a buffer overflow in memory due to incorrect use of glib's base64 decode functionality. This can be exploited by a remote attacker using a specially crafted request with an invalid
base64-encoded cookie, potentially leading to a denial of service.Recommendations
For versions prior to 184, update to version 184 or later to resolve the issue. As a temporary workaround, consider restricting access to the web service to minimize the risk of exploitation.
Fix
DoS
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Cockpit
Red Hat