Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-1167

Опубликовано: 06 апр. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-1167: nbdkit security and bug fix update (LOW)

[1.8.0-3]

  • Fix for CVE-2019-14850 denial of service due to premature opening of back-end connection resolves: rhbz#1757261

[1.8.0-2]

  • Explicitly disable nbdkit-ext2-plugin in configure resolves: rhbz#1724242

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

nbdkit

1.8.0-3.el7

nbdkit-basic-plugins

1.8.0-3.el7

nbdkit-devel

1.8.0-3.el7

nbdkit-example-plugins

1.8.0-3.el7

nbdkit-plugin-python-common

1.8.0-3.el7

nbdkit-plugin-python2

1.8.0-3.el7

nbdkit-plugin-vddk

1.8.0-3.el7

Связанные CVE

Связанные уязвимости

CVSS3: 3.7
ubuntu
почти 5 лет назад

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.

CVSS3: 3.7
redhat
больше 6 лет назад

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.

CVSS3: 3.7
nvd
почти 5 лет назад

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.

CVSS3: 3.7
debian
почти 5 лет назад

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.1 ...

github
больше 3 лет назад

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.