漏洞信息详情
libcares2 跨站脚本漏洞
漏洞简介
libcares2是openSUSE项目的一个 C 库,可以异步执行 DNS 请求和名称解析。
libcares2 存在跨站脚本漏洞,该漏洞源于对主机名的输入验证不当。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.suse.com/support/update/announcement/2021/suse-su-202114776-1/
参考网址
来源:MISC
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1988342
来源:MISC
链接:https://c-ares.haxx.se/adv_20210810.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2907
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163774/Ubuntu-Security-Notice-USN-5034-1.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/c-ares-spoofing-via-Zero-Byte-Hostnames-36085
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3219
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164299/Red-Hat-Security-Advisory-2021-3666-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021093017
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2858
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2782
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-3672
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3231
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2790
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2950
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3445
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2685
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163937/Red-Hat-Security-Advisory-2021-3280-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2993
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3169
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021110508
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2695
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164257/Red-Hat-Security-Advisory-2021-3638-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163791/Ubuntu-Security-Notice-USN-5034-2.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164229/Red-Hat-Security-Advisory-2021-3623-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3196
受影响实体
暂无
补丁
- SUSE Linux Enterprise Server 安全漏洞的修复措施<!--2021-8-10-->
还没有评论,来说两句吧...