Описание
A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout management during network read operations.
A flaw was found in libmodbus. This Denial of Service (DoS) vulnerability exists in the receive loop when the software is running on Windows. The issue is caused by improper timeout management during network read operations, which can allow a remote attacker to cause the application to become unresponsive.
Отчет
Red Hat distributes libmodbus only as a Linux package, via Fedora and EPEL, and does not ship or support a Windows build. Because Linux's select() semantics do not exhibit the behavior this flaw depends on, libmodbus as built and shipped by Red Hat is not exposed to the attack described.
Меры по смягчению последствий
No mitigation is required to protect the Fedora or EPEL builds of libmodbus, since Red Hat only ships Linux builds, which are not subject to the timeout-bypass behavior this issue depends on.
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout management during network read operations.
A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout management during network read operations.
EPSS
7.5 High
CVSS3