CVE-2019-3804
26.03.2019, 18:29
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.Enginsight
| Vendor | Product | Version |
|---|---|---|
| cockpit-project | cockpit | 𝑥 < 184 |
| fedoraproject | fedora | - |
| redhat | virtualization | 4.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References