Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-53580

Опубликовано: 18 дек. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

A flaw was found in iperf. This vulnerability allows a Denial of Service (DoS) via the injection of malformed JSON data, which can result in a segmentation fault when a NULL pointer is passed to strdup().

Отчет

This vulnerability marked as important severity rather than moderate due to its potential to cause a complete denial of service (DoS) by exploiting a segmentation fault through malformed JSON data. The flaw stems from improper input validation, which allows attackers to crash the server by sending invalid data that triggers memory mismanagement. Since iperf is widely used in performance testing of network systems, a DoS attack could disrupt critical operations in production environments, leading to service outages or performance degradation in large-scale networks.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2333146iperf: Denial of Service in iperf Due to Improper JSON Handling

EPSS

Процентиль: 48%
0.00248
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 месяцев назад

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

CVSS3: 7.5
nvd
8 месяцев назад

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

CVSS3: 7.5
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
8 месяцев назад

iperf v3.17.1 was discovered to contain a segmentation violation via t ...

suse-cvrf
6 месяцев назад

Security update for iperf

EPSS

Процентиль: 48%
0.00248
Низкий

7.5 High

CVSS3