6.4
CVSSv2

CVE-2021-36159

Published: 03/08/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 571
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

libfetch prior to 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols. The FTP passive mode implementation allows an out-of-bounds read because strtol is used to parse the relevant numbers into address bytes. It does not check if the line ends prematurely. If it does, the for-loop condition checks for the '\0' terminator one byte too late.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd libfetch

Github Repositories

Sinker is a Python tool to automate the execution of dockerized container scanning security tools merging their findings into one report.

Sinker 🐙 Sinker is a Python tool to automate: execution of dockerized container scanning tools; merge of multiple reports; post-execution tasks Why? Running these tools manually can be boring and time-consuming when there are multiple images and deployments Parsing their reports manually to get a unified view of the findings is challenging Which container scanning tool (

This library is designed to check the vulnerabilities that exists in the vendor images and bitnami images and to recommend the better image with lesser vulnerabilities.

Container Image Vulnerability Checker and Image Recommender using Twistlock and Synk: This library is designed to check the vulnerabilites that exists in the vendor images and bitnami images and to recommend the better image with lesser vulnerabilities Images that are to compared can be configured in the configjson file { "login": " -u <<username&

This library is designed to check the vulnerabilities that exists in the vendor images and bitnami images and to recommend the better image with lesser vulnerabilities.

Container Image Vulnerability Checker and Image Recommender using Twistlock and Synk: This library is designed to check the vulnerabilites that exists in the vendor images and bitnami images and to recommend the better image with lesser vulnerabilities Images that are to compared can be configured in the configjson file { "login": " -u <<username&

Product Report: Django-NV Generated By Admin User (admin) on 12/23/2021 07:55PM UTC Number of vulnerabilities found: 15 VULNERABILITIES DESCRIPTION VULNERABILITY ID : 9 TITLE: Starting a Process With a Shell, Possible Injection Detected, Security Issue SEVERITY: High RECOMMENDED TIME TO RESOLVE THE ISSUE: 30 days DESCRIPTION: An SQL injection attack consists of insertion or &l