CVE-2018-5704P3CRITICALCVSS 9.6fixed in openocd 0.10.0-4 (bookworm)2018
CVE-2018-5704 [CRITICAL] CVE-2018-5704: openocd - Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST ...
Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.
Scope: local
bookworm: resolved (fixed in 0.10.0-4)
bullseye: resolved (fixed in 0.10.0-4)
forky: res
debian