Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-25824

Опубликовано: 23 фев. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the transport hit timeouts. Instead it entered an endless loop retrying the read operation, consuming CPU resources. This could be exploited for denial of service attacks. If trace level logging was enabled, it would also produce an excessive amount of log output during the loop, consuming disk space. The problem has been fixed in commit d7eec4e598158ab6a98bf505354e84352f9715ec, please update to version 0.12.1. There are no workarounds, users who cannot update should apply the errno fix detailed in the security advisory.

РелизСтатусПримечание
bionic

not-affected

code not present
devel

DNE

esm-apps/bionic

not-affected

code not present
esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/xenial

not-affected

code not present
focal

ignored

end of standard support, was needed
jammy

needed

kinetic

not-affected

code not present
lunar

ignored

end of life, was needs-triage

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the transport hit timeouts. Instead it entered an endless loop retrying the read operation, consuming CPU resources. This could be exploited for denial of service attacks. If trace level logging was enabled, it would also produce an excessive amount of log output during the loop, consuming disk space. The problem has been fixed in commit d7eec4e598158ab6a98bf505354e84352f9715ec, please update to version 0.12.1. There are no workarounds, users who cannot update should apply the errno fix detailed in the security advisory.

CVSS3: 7.5
debian
почти 3 года назад

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions ...

7.5 High

CVSS3

Уязвимость CVE-2023-25824