Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7401

Опубликовано: 13 фев. 2017
Источник: redhat
CVSS3: 5.9

Описание

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.

collectd contains an infinite loop due to how the parse_packet() and parse_part_sign_sha256() functions interact. If an instance of collectd is configured with "SecurityLevel None" and empty "AuthFile" options, an attacker can send crafted UDP packets that trigger the infinite loop, causing a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational ToolscollectdWill not fix
Red Hat OpenStack Platform 10 (Newton) Operational ToolscollectdWill not fix
Red Hat OpenStack Platform 12 (Pike) Operational ToolscollectdNot affected
Red Hat OpenStack Platform 8 (Liberty) Operational ToolscollectdWill not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational ToolscollectdWill not fix
Red Hat Storage Console 2collectdWill not fix
Red Hat Gluster Storage 3.4 for RHEL 7collectdFixedRHSA-2018:261504.09.2018
Red Hat OpenStack Platform 11.0 Operational Tools for RHEL 7collectdFixedRHSA-2017:178719.07.2017
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7collectdFixedRHSA-2017:128524.05.2017
Red Hat Virtualization Engine 4.1collectdFixedRHSA-2017:128524.05.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1439674collectd: Infinite loop due to incorrect interaction of parse_packet() and parse_part_sign_sha256() functions

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.

CVSS3: 7.5
nvd
почти 9 лет назад

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.

CVSS3: 7.5
debian
почти 9 лет назад

Incorrect interaction of the parse_packet() and parse_part_sign_sha256 ...

CVSS3: 7.5
github
больше 3 лет назад

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.

5.9 Medium

CVSS3