Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-4785

Опубликовано: 13 сент. 2023
Источник: debian
EPSS Низкий

Описание

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
grpcunfixedpackage
grpcno-dsatrixiepackage
grpcno-dsabookwormpackage
grpcno-dsabullseyepackage
grpcno-dsabusterpackage

Примечания

  • https://github.com/grpc/grpc/pull/33656

  • https://github.com/grpc/grpc/pull/33667

  • https://github.com/grpc/grpc/pull/33669

  • https://github.com/grpc/grpc/pull/33670

  • https://github.com/grpc/grpc/pull/33672

EPSS

Процентиль: 4%
0.00018
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

CVSS3: 7.5
redhat
больше 2 лет назад

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. 

CVSS3: 7.5
nvd
больше 2 лет назад

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
github
больше 2 лет назад

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

EPSS

Процентиль: 4%
0.00018
Низкий