Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7401

Опубликовано: 03 апр. 2017
Источник: debian

Описание

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
collectdfixed5.7.2-1package
collectdno-dsastretchpackage
collectdno-dsajessiepackage

Примечания

  • https://github.com/collectd/collectd/issues/2174

  • https://github.com/collectd/collectd/commit/f6be4f9b49b949b379326c3d7002476e6ce4f211

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.

CVSS3: 5.9
redhat
почти 9 лет назад

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.

CVSS3: 7.5
nvd
почти 9 лет назад

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.

CVSS3: 7.5
github
больше 3 лет назад

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.