Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-14850

Опубликовано: 18 мар. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6
CVSS3: 3.7

Описание

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

1.24.1-2ubuntu4
disco

ignored

end of life
eoan

ignored

end of life
esm-apps-legacy/xenial

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

not-affected

1.24.1-2ubuntu4
esm-apps/resolute

not-affected

1.24.1-2ubuntu4
esm-apps/xenial

ignored

end of ESM support, was needs-triage

Показывать по

EPSS

Процентиль: 73%
0.01601
Низкий

2.6 Low

CVSS2

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
почти 7 лет назад

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.

CVSS3: 3.7
nvd
больше 5 лет назад

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.

CVSS3: 3.7
debian
больше 5 лет назад

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.1 ...

github
около 4 лет назад

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.

oracle-oval
больше 6 лет назад

ELSA-2020-1167: nbdkit security and bug fix update (LOW)

EPSS

Процентиль: 73%
0.01601
Низкий

2.6 Low

CVSS2

3.7 Low

CVSS3