Vulnerability Description
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator. The attack vector is: Remote unauthenticated. The fixed version is: after commit 5267b455caeb2e055cccf0d2b6a22727c111f5c3.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teller | Slanger | 0.6.0 |
Related Weaknesses (CWE)
References
- https://github.com/stevegraham/slanger/pull/238/commits/5267b455caeb2e055cccf0d2PatchThird Party Advisory
- https://github.com/stevegraham/slanger/pull/238/commits/5267b455caeb2e055cccf0d2PatchThird Party Advisory
FAQ
What is CVE-2019-1010306?
CVE-2019-1010306 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler...
How severe is CVE-2019-1010306?
CVE-2019-1010306 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-1010306?
Check the references section above for vendor advisories and patch information. Affected products include: Teller Slanger.