5
CVSSv2

CVE-2015-5185

Published: 28/09/2015 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via an empty className in a packet.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.2

opensuse opensuse 13.1

standards based linux instrumentation sblim-sfcb 1.3.4

standards based linux instrumentation sblim-sfcb 1.3.18

Vendor Advisories

A NULL pointer dereference flaw was found in the way the lookupProviders() function processed certain requests without "className" information An authenticated remote attacker could use this flaw to cause a denial of service (sfcbd crash) by sending a specially crafted request ...