Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14851

Опубликовано: 20 сент. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.

Меры по смягчению последствий

If nbdkit is configured with TLS client authentication, only trusted clients can carry out this attack. Only attackers that can connect to the nbdkit service can exploit this vulnerability. If nbdkit is not exposed over TCP (eg, nbdkit -U), or is bound only to a private network interface, or is protected by firewall rules, the attack surface is correspondingly limited.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7nbdkitNot affected
Red Hat Enterprise Linux 8nbdkitNot affected
Red Hat Enterprise Linux 8 Advanced VirtualizationnbdkitNot affected
Red Hat Virtualization 4nbdkitNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1757259nbdkit: assertion failure by issuing commands in the wrong order

EPSS

Процентиль: 56%
0.00332
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 5 лет назад

A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.

CVSS3: 6.5
nvd
почти 5 лет назад

A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.

CVSS3: 6.5
debian
почти 5 лет назад

A denial of service vulnerability was discovered in nbdkit. A client i ...

github
больше 3 лет назад

A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.

EPSS

Процентиль: 56%
0.00332
Низкий

6.5 Medium

CVSS3