PT-2017-6605 · Gnome+2 · Librest+2

·

CVE-2015-2675

·

Published

2015-11-19

·

Updated

2023-02-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions librest versions prior to 0.7.93
Description The issue is related to the OAuth implementation in librest, which incorrectly truncates a pointer returned by the rest proxy call get url function. This can be exploited by remote attackers to cause a denial of service, resulting in an application crash. The attack can be performed by running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.
Recommendations For versions prior to 0.7.93, update to version 0.7.93 or later to resolve the issue.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2015_2237
CVE-2015-2675
RHSA-2015:2237
RHSA-2015_2237

Affected Products

Centos
Red Hat
Librest