Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-54349

Опубликовано: 03 авг. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

A flaw was found in iperf3. An off-by-one error in the iperf_auth.c file leads to a heap-based buffer overflow, potentially allowing a network attacker to trigger an application-level denial of service. This overflow occurs during the processing of authentication data. The vulnerability can only be exploited with direct network access.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10iperf3Fix deferred
Red Hat Enterprise Linux 7iperf3Fix deferred
Red Hat Enterprise Linux 8iperf3Fix deferred
Red Hat Enterprise Linux 9iperf3Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=2386151iperf3: iperf Heap Buffer Overflow

EPSS

Процентиль: 11%
0.00041
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
26 дней назад

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

CVSS3: 6.5
nvd
26 дней назад

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

CVSS3: 6.5
debian
26 дней назад

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resul ...

CVSS3: 6.5
github
26 дней назад

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

EPSS

Процентиль: 11%
0.00041
Низкий

6.5 Medium

CVSS3