Beveiligingsadvies

CVE-2018-4012

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-01-03 23:00:00
Laatst bijgewerkt 2024-08-05 04:57:24
Toegewezen door talos
CVSS-score 9.0
Status PUBLISHED

Beschrijving

An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud server to trigger this vulnerability.