PT-2017-17710 · Collectd+2 · Collectd+2

Marcinguyo

·

Publicado

2017-04-03

·

Atualizado

2021-03-15

·

CVE-2017-7401

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions collectd versions 5.7.1 and earlier
Description The issue arises from the incorrect interaction between the parse packet() and parse part sign sha256() functions in network.c, allowing remote attackers to cause a denial of service (infinite loop) in a collectd instance. This can occur when the collectd instance is configured with "SecurityLevel None" and has empty "AuthFile" options, and a crafted UDP packet is sent.
Recommendations For collectd versions 5.7.1 and earlier, consider updating to a version that addresses this issue, as the current version allows for a denial of service attack via a crafted UDP packet. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1996
CVE-2017-7401
DLA-884-1
OPENSUSE-SU-2024:10691-1
RHSA-2017:1285
RHSA-2017:1787
RHSA-2018:2615
SUSE-SU-2017:1365-1
USN-4793-1

Produtos afetados

Alt Linux
Ubuntu
Collectd