Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:9185

Опубликовано: 17 мар. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: iperf3 security update

Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.

Security Fix(es):

  • iperf3: possible denial of service (CVE-2023-7250,ESNET-SECADV-2023-0002)

  • iperf3: vulnerable to marvin attack if the authentication option is used (CVE-2024-26306)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.5 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
iperf3i68613.el9_5.1iperf3-3.9-13.el9_5.1.i686.rpm
iperf3x86_6413.el9_5.1iperf3-3.9-13.el9_5.1.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

rocky
6 месяцев назад

Moderate: iperf3 security update

oracle-oval
12 месяцев назад

ELSA-2024-9185: iperf3 security update (MODERATE)

oracle-oval
больше 1 года назад

ELSA-2024-4241: iperf3 security update (MODERATE)

CVSS3: 5.3
ubuntu
больше 1 года назад

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.

CVSS3: 5.3
redhat
около 2 лет назад

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.