VDB
CVE-2021-3466
CVE-2021-3466
PUBLISHED
CVSS 10 CRITICAL
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.
EPSS 0.42% · 62.3th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
0.42%
62.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | enterprise_linux | 7.0, 8.0, 6.0 |
| fedoraproject | fedora | 32, 33, 34 |
| n/a | libmicrohttpd | * |
| gnu | libmicrohttpd | 0.9.70 |
Timeline
- Mar 25, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- May 5, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1939127 url
- FEDORA-2021-6d5578e756 vendor-advisory
- FEDORA-2021-d4149ff7fb vendor-advisory
- FEDORA-2021-5e10ad8c19 vendor-advisory
- GLSA-202311-08 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3466 advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4334XJNDJPYQNFE6S3S2KUJJ7TMHYCWL url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/75HDMREKITMGPGE62NP7KE62ZJVLETXN url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K5NEPVGP3L2CZHLZ4UB44PEILHKPDBOG url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4334XJNDJPYQNFE6S3S2KUJJ7TMHYCWL url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/75HDMREKITMGPGE62NP7KE62ZJVLETXN url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K5NEPVGP3L2CZHLZ4UB44PEILHKPDBOG url