Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Richard W. M. Jones

Researcher fromRed Hat
#52603of 53,638
3.7Total CVSS
Vulnerabilities · 1
PT-2021-8984
3.7
2020-03-31
Nbdkit · Nbdkit · CVE-2019-14850
**Name of the Vulnerable Software and Affected Versions** nbdkit versions 1.12.7, 1.14.1, 1.15.1 **Description** A denial of service issue was discovered in nbdkit. An attacker could connect to the nbdkit service, causing it to perform a large amount of work in initializing backend plugins by simply opening a connection to the service. This could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side. **Recommendations** For version 1.12.7, update to a version that fixes this issue. For version 1.14.1, update to a version that fixes this issue. For version 1.15.1, update to a version that fixes this issue. As a temporary workaround, consider restricting access to the nbdkit service to minimize the risk of exploitation.