Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-7250

Опубликовано: 18 мар. 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iperf3fixed3.15-1package
iperf3ignoredbookwormpackage
iperf3no-dsabusterpackage

Примечания

  • https://downloads.es.net/pub/iperf/esnet-secadv-2023-0002.txt.asc

  • https://github.com/esnet/iperf/commit/5e3704dd850a5df2fb2b3eafd117963d017d07b4 (3.15)

EPSS

Процентиль: 13%
0.00045
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.

CVSS3: 5.3
redhat
почти 2 года назад

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.

CVSS3: 5.3
nvd
больше 1 года назад

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.

CVSS3: 5.3
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.3
redos
больше 1 года назад

Уязвимость iperf3

EPSS

Процентиль: 13%
0.00045
Низкий