CVE-2021-0613
published 2021-10-25CVE-2021-0613: In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.11%
1.6th percentile
In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05489178.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
ghsa6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-982j-w6p4-6qqc: In asf extractor, there is a possible out of bounds read due to an incorrect bounds check
ghsa_unreviewed·2022-05-24
CVE-2021-0613 [MEDIUM] CWE-125 GHSA-982j-w6p4-6qqc: In asf extractor, there is a possible out of bounds read due to an incorrect bounds check
In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05489178.
GHSA
Authorization Bypass Through User-Controlled Key in urijs
ghsa·2022-02-17·CVSS 6.1
CVE-2022-0613 [MEDIUM] CWE-639 Authorization Bypass Through User-Controlled Key in urijs
Authorization Bypass Through User-Controlled Key in urijs
Attacker can use case-insensitive protocol schemes like HTTP, htTP, HTtp etc. in order to bypass the patch for CVE-2021-3647.
Red Hat
urijs: Authorization Bypass Through User-Controlled Key
vendor_redhat·2022-02-16·CVSS 6.1
CVE-2022-0613 [MEDIUM] CWE-639 urijs: Authorization Bypass Through User-Controlled Key
urijs: Authorization Bypass Through User-Controlled Key
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
A flaw was found in urijs due to the fix of CVE-2021-3647 not considering case-sensitive protocol schemes in the URL. This issue allows attackers to bypass the patch.
Package: rh-dotnet50-dotnet (.NET Core 5.0 on Red Hat Enterprise Linux) - Out of support scope
Package: rhacm2/application-ui-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Affected
Package: rhacm2/mcm-topology-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Will not fix
Package: dotnet5.0 (Red Hat Enterprise Linux 8) - Will not fix
Package: quay/quay-rhel8 (Red Hat Quay 3) - Affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-25
Published