Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-39480: memory allocation of 18446744073709551610 bytes failed[1] · Issue #30 · m4b/bingrep

Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).

CVE
#dos

HI !
I found a memory allocation of 18446744073709551610 bytes failed in the current master e232665
POC : poc.zip

$ ./bingrep out/default/crashes/poc 
ELF EXEC EM_UNKNOWN-little-endian @ 0x8049080:

e_phoff: 0x80 e_shoff: 0xc e_flags: 0x10000 e_ehsize: 0 e_phentsize: 3 e_phnum: 0 e_shentsize: 36992 e_shnum: 2 e_shstrndx: 0

ProgramHeaders(0):
  

SectionHeaders(2):
memory allocation of 18446744073709551610 bytes failed[1]    552937 abort      ./bingrep out/default/crashes/poc

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907