VDB
BDU%3A2024-02279
BDU%3A2024-02279
PUBLISHED
CVSS 10 CRITICAL
Уязвимость библиотеки для обработки байт-кода Java Apache Commons BCEL, связанная с записью за границами буфера, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, Fedora Project, ООО «Ред Софт», JetBrains, Apache Software Foundation | Red Hat Enterprise Linux, Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, Debian GNU/Linux, Red Hat Single Sign-On, openSUSE Tumbleweed, Red Hat JBoss Data Grid, Jboss Fuse, SUSE Linux Enterprise Module for Basesystem, OpenSUSE Leap, Fedora, Red Hat JBoss Fuse Service Works, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise High Performance Computing, SUSE Manager Proxy, SUSE Manager Server, Suse Linux Enterprise Desktop, SUSE Manager Retail Branch Server, SUSE Enterprise Storage, Red Hat JBoss Enterprise Application Platform, SUSE Liberty Linux, Red Hat Software Collections for Red Hat Enterprise Linux, Red Hat Fuse, Scala Plugin for IntelliJ IDEA, Migration Toolkit for Runtimes, Migration Toolkit for Applications, Red Hat Process Automation Manager, Commons BCEL |
Timeline
- Mar 25, 2024 CVE Published
- Aug 6, 2024 CVE Updated
References
- http://www.openwall.com/lists/oss-security/2022/11/07/2 url
- https://lists.apache.org/thread/lfxk7q8qmnh5bt9jm6nmjlv5hsxjhrz4 url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LX3HEB4TV2BVCGDTK5BCLSYOZNQTOBN4/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QAMRHAKGIKZNHRBB4VLYTOIOIMMXCUCD/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMVX6COVXZVS5GPWDODIRW6Z2GE7RPAQ/ url
- https://security.gentoo.org/glsa/202401-25 url
- https://www.suse.com/security/cve/CVE-2022-42920.html url
- https://access.redhat.com/security/cve/CVE-2022-42920 url
- https://security-tracker.debian.org/tracker/CVE-2022-42920 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url